CVE-2013-4809SQL Injection in HP Identity Driven Manager

CWE-89SQL Injection3 documents3 sources
Severity
7.5HIGHNVD
EPSS
0.9%
top 24.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 16
Latest updateMay 17

Description

Multiple SQL injection vulnerabilities in GetEventsServlet in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity Driven Manager (IDM) 4.0 allow remote attackers to execute arbitrary SQL commands via the (1) sort or (2) dir parameter.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-j6cg-84jw-7v8h: Multiple SQL injection vulnerabilities in GetEventsServlet in HP ProCurve Manager (PCM) 32022-05-17
CVEList
CVE-2013-4809: Multiple SQL injection vulnerabilities in GetEventsServlet in HP ProCurve Manager (PCM) 32013-09-13
CVE-2013-4809 — SQL Injection in HP | cvebase