CVE-2013-2366
HP Business Process Monitor tp_bpm_admin.exe Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Unspecified vulnerability in HP Business Process Monitor 9.13.1 patch 1 and 9.22 patch 1 allows remote attackers to execute arbitrary code and obtain sensitive information via unknown vectors, aka ZDI-CAN-1802.
Vulnerabilidad no especificada en HP Business Process Monitor 9.13.1 parche 1, y 9.22 parche 1 permite a atacantes remotos ejecutar código de forma arbitraria y obtener información sensible a través de vectores desconocidos, tambien conocido como ZDI-CAN-1802.
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of HP Business Process Monitor. Authentication is not required to exploit this vulnerability.
The specific flaw exists in the handling of requests to the tp_bpm_admin.exe server which listens by default on TCP port 2696. This server exposes file upload functionality that is vulnerable to a directory traversal. This can be leveraged by an attacker to gain remote code execution under the context of SYSTEM.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2013-03-04 CVE Reserved
- 2013-10-11 CVE Published
- 2024-09-17 CVE Updated
- 2024-09-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03844594 | 2019-10-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ibm Search vendor "Ibm" | Business Process Monitor Search vendor "Ibm" for product "Business Process Monitor" | 9.13.1 Search vendor "Ibm" for product "Business Process Monitor" and version "9.13.1" | patch1 |
Affected
| ||||||
Ibm Search vendor "Ibm" | Business Process Monitor Search vendor "Ibm" for product "Business Process Monitor" | 9.22 Search vendor "Ibm" for product "Business Process Monitor" and version "9.22" | patch1 |
Affected
|