Multiple SQL injection vulnerabilities in GetEventsServlet in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity Driven Manager (IDM) 4.0 allow remote attackers to execute arbitrary SQL commands via the (1) sort or (2) dir parameter.
2013-09-16T13:01:46.190
2025-04-22T14:51:37.563
Deferred
CVSSv2: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | hp | identity_driven_manager | 4.0 | Yes |
Application | hp | procurve_manager | 3.20 | Yes |
Application | hp | procurve_manager | 4.0 | Yes |