Vulnerability Name: | CVE-2013-6202 (CCN-91371) | ||||||||
Assigned: | 2013-10-21 | ||||||||
Published: | 2014-02-20 | ||||||||
Updated: | 2019-10-09 | ||||||||
Summary: | Multiple cross-site request forgery (CSRF) vulnerabilities in HP Service Manager 9.30, 9.31, 9.32, and 9.33 allow remote attackers to hijack the authentication of unspecified victims for requests that (1) insert XSS sequences or (2) execute arbitrary code. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P) 5.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:H/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-352 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2013-6202 Source: HP Type: Vendor Advisory SSRT101437 Source: CCN Type: SA57065 HP Service Manager Multiple Vulnerabilities Source: CCN Type: BID-65736 HP Service Manager CVE-2013-6202 Multiple Security Vulnerabilities Source: SECTRACK Type: UNKNOWN 1029803 Source: XF Type: UNKNOWN hp-service-unspec-csrf(91371) Source: CCN Type: HP Security Bulletin HPSBMU02964 HP Service Manager, Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF), Remote Denial of Service (DoS), Execution of Arbitrary Code, Unauthorized Access, Disclosure of Information and Authentication Issues | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |