CVE ID | CVE-2017-14350 |
CVSS SCORE | 10.0, AV:N/AC:L/Au:N/C:C/I:C/A:C |
AFFECTED VENDORS |
Hewlett Packard Enterprise |
AFFECTED PRODUCTS |
Application Performance Management Staging Data Replicator |
VULNERABILITY DETAILS |
The specific flaw exists within the hpbsmsdr web service, which listens on TCP port 29921 by default. The software does not provide any authentication for functionality that can invoke arbitrary classes. An attacker can leverage this vulnerability to execute code under the context of SYSTEM.
|
ADDITIONAL DETAILS |
Hewlett Packard Enterprise has issued an update to correct this vulnerability. More details can be found at:
http://seclists.org/bugtraq/2017/Sep/31 |
DISCLOSURE TIMELINE |
|
CREDIT | rgod |