Imperva SecureSphere Operations Manager CVE-2013-4095 Arbitrary Command Execution Vulnerability
BID:61067
Info
Imperva SecureSphere Operations Manager CVE-2013-4095 Arbitrary Command Execution Vulnerability
| Bugtraq ID: | 61067 |
| Class: | Unknown |
| CVE: |
CVE-2013-4095 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 02 2013 12:00AM |
| Updated: | Jun 02 2013 12:00AM |
| Credit: | Pedro Andujar |
| Vulnerable: |
Imperva SecureSphere Operations Manager 9.0.0.5 |
| Not Vulnerable: | |
Discussion
Imperva SecureSphere Operations Manager CVE-2013-4095 Arbitrary Command Execution Vulnerability
Imperva SecureSphere Operations Manager is prone to an arbitrary command-execution vulnerability.
An attacker can exploit this issue to execute arbitrary commands in the context of the application.
Imperva SecureSphere Operations Manager 9.0.0.5 is vulnerable; other versions may also be affected.
NOTE: This issue was previously covered in BID 60286 (Imperva SecureSphere Operations Manager Multiple Security Vulnerabilities) but has been given its own record for better documentation.
Imperva SecureSphere Operations Manager is prone to an arbitrary command-execution vulnerability.
An attacker can exploit this issue to execute arbitrary commands in the context of the application.
Imperva SecureSphere Operations Manager 9.0.0.5 is vulnerable; other versions may also be affected.
NOTE: This issue was previously covered in BID 60286 (Imperva SecureSphere Operations Manager Multiple Security Vulnerabilities) but has been given its own record for better documentation.
Exploit / POC
Imperva SecureSphere Operations Manager CVE-2013-4095 Arbitrary Command Execution Vulnerability
The researcher who discovered this issue has created a proof-of-concept. Please see the references for more information.
The researcher who discovered this issue has created a proof-of-concept. Please see the references for more information.
Solution / Fix
Imperva SecureSphere Operations Manager CVE-2013-4095 Arbitrary Command Execution Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Imperva SecureSphere Operations Manager CVE-2013-4095 Arbitrary Command Execution Vulnerability
References:
References: