{"api_version":"1","generated_at":"2026-07-23T08:57:05+00:00","cve":"CVE-2017-12527","urls":{"html":"https://cve.report/CVE-2017-12527","api":"https://cve.report/api/cve/CVE-2017-12527.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-12527","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-12527"},"summary":{"title":"CVE-2017-12527","description":"A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.","state":"PUBLIC","assigner":"security-alert@hpe.com","published_at":"2018-02-15 22:29:00","updated_at":"2018-02-23 18:49:00"},"problem_types":["CWE-20"],"metrics":[],"references":[{"url":"http://www.securityfocus.com/bid/100367","name":"100367","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"HP Intelligent Management Center PLAT Multiple Remote Code Execution Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbhf03768en_us","name":"https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbhf03768en_us","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Document Display | HPE Support Center","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1039152","name":"1039152","refsource":"SECTRACK","tags":["Third Party Advisory","VDB Entry"],"title":"HPE Intelligent Management Center PLAT Multiple JSF Expression Language Injection Flaws Let Remote Authenticated Users Execute Arbitrary Code on the Target System - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-12527","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-12527","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"12527","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hp","cpe5":"intelligent_management_center","cpe6":"7.3","cpe7":"e0504","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"12527","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hp","cpe5":"intelligent_management_center","cpe6":"7.3","cpe7":"e0504","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"security-alert@hpe.com","DATE_PUBLIC":"2017-08-11T00:00:00","ID":"CVE-2017-12527","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Intelligent Management Center (iMC) PLAT","version":{"version_data":[{"version_value":"PLAT 7.3 (E0504)"}]}}]},"vendor_name":"Hewlett Packard Enterprise"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Remote Code Execution"}]}]},"references":{"reference_data":[{"name":"1039152","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1039152"},{"name":"100367","refsource":"BID","url":"http://www.securityfocus.com/bid/100367"},{"name":"https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbhf03768en_us","refsource":"CONFIRM","url":"https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbhf03768en_us"}]}},"nvd":{"publishedDate":"2018-02-15 22:29:00","lastModifiedDate":"2018-02-23 18:49:00","problem_types":["CWE-20"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:C/I:C/A:C","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":9},"severity":"HIGH","exploitabilityScore":8,"impactScore":10,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:hp:intelligent_management_center:7.3:e0504:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"12527","Ordinal":"109676","Title":"CVE-2017-12527","CVE":"CVE-2017-12527","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"12527","Ordinal":"1","NoteData":"A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.","Type":"Description","Title":null},{"CveYear":"2017","CveId":"12527","Ordinal":"2","NoteData":"2018-02-15","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"12527","Ordinal":"3","NoteData":"2018-02-16","Type":"Other","Title":"Modified"}]}}}