PT-2013-5234 · Hewlett Packard · Hp Application Lifecycle Management

Published

2013-11-04

·

Updated

2019-10-09

·

CVE-2013-4836

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions HP Application LifeCycle Management versions prior to 1.4.2
Description The issue allows remote attackers to execute arbitrary code via unknown vectors. This is related to an unspecified vulnerability in the GossipService SOAP Request implementation in the Synchronizer component.
Recommendations For versions prior to 1.4.2, update to version 1.4.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the GossipService SOAP Request implementation until a patch is applied.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2013-4836
ZDI-13-262

Affected Products

Hp Application Lifecycle Management