LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2013-4810: HP Multiple Products Remote Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 25, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Apr 15, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2013-4810 to its Known Exploited Vulnerabilities catalog on Mar 25, 2022, with a federal patch deadline of Apr 15, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

HP ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to (1) EJBInvokerServlet…

CVE-2013-4810 is a remote code execution vulnerability in Hewlett Packard ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management. Attackers can send specially crafted marshalled objects to certain invoker servlets and run arbitrary code on the host. For teams still running these network and identity management products, the issue matters because successful abuse can give an unauthenticated remote attacker control of the management server and the systems it administers.

Public detail is limited to the products and attack surface named above; confirm exact version ranges, patches, and deployment notes against the vendor advisory before acting.

How it works

The weakness is classified as CWE-94 (code injection). In these HP products the EJBInvokerServlet and JMXInvokerServlet accept serialized (marshalled) Java objects. An attacker who can reach those endpoints can supply a malicious object that the server deserializes and processes, leading to execution of attacker-chosen code in the context of the application service.

No further exploit mechanics, payloads, or preconditions are provided in the available record. Treat any internet- or network-reachable instance of the listed invoker servlets as potentially exploitable until the vendor update is applied and the configuration is verified.

Am I affected? How to find it in your systems

These components typically run on management servers used for HP ProCurve/Aruba-style network administration, identity policy, or application lifecycle functions. They are often installed on Windows or Linux hosts inside data-center or network-operations segments and may expose HTTP/HTTPS management ports.

How to remediate

Patch first. Apply the updates published by Hewlett Packard for the affected products exactly as described in the vendor advisory. CISA’s required action is to apply updates per vendor instructions.

If you can't patch immediately

Until the vendor update can be installed, reduce exposure with compensating controls appropriate to remote code-execution flaws in management servers:

If your data may have been exposed

Actively exploited remote-code-execution vulnerabilities on management platforms frequently precede broader compromise and data theft. Known ransomware use of this CVE is not documented, but any confirmed intrusion should be treated as a potential breach. Contain the host, preserve logs and memory images, and follow your incident-response process. As a quick additional check, you can run a free exposure scan of your email addresses against known breach data sets to see whether credentials or personal information have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedHewlett Packard (HP) · ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management
WeaknessCWE-94
Added to CISA KEVMar 25, 2022
Federal patch deadlineApr 15, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities