The Java Glassfish Admin Console in HP Executive Scorecard 9.40 and 9.41 does not require authentication, which allows remote attackers to execute arbitrary code via a session on TCP port 10001, aka ZDI-CAN-2116.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04341295 | vendor advisory |
http://secunia.com/advisories/59363 | third party advisory |
http://zerodayinitiative.com/advisories/ZDI-14-208/ | |
http://www.securityfocus.com/bid/68093 | vdb entry |
http://www.securitytracker.com/id/1030439 | vdb entry |