HP Business Service Management (BSM) 9.12 does not properly restrict the uploading of .war files, which allows remote malicious users to execute arbitrary JSP code within the JBOSS Application Server component via a crafted request to TCP port 1098, 1099, or 4444.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
hp business service management 9.12 |