7.5
CVSSv2

CVE-2013-4809

Published: 16/09/2013 Updated: 26/09/2013
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in GetEventsServlet in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity Driven Manager (IDM) 4.0 allow remote malicious users to execute arbitrary SQL commands via the (1) sort or (2) dir parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

hp procurve manager 4.0

hp identity driven manager 4.0

hp procurve manager 3.20