HTTP: HPE Intelligent Management Center accessMgrServlet Insecure Deserialization

An insecure deserialization vulnerability has been reported in HPE Intelligent Management Center. Successful exploitation results in arbitrary code execution under the context of the SYSTEM or root user.

Extended Description

A remote deserialization of untrusted data vulnerability in HPE Intelligent Management Center (IMC) PLAT version 7.2 E0403P06 was found.

Affected Products

Hp intelligent_management_center

Short Name
HTTP:HPE-ACCESS-DESERIALIZATION
Severity
Major
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2017-5790 Center Deserialization HPE Insecure Intelligent Management accessMgrServlet
Release Date
03/28/2017
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3680
False Positive
Unknown
Vendors

Hp

CVSS Score

10.0

Found a potential security threat?