CVE-2013-4094
MEDIUM 6.5EPSS 5.6%
The Key Management feature in the SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote authenticated users to upload executable files via the (1) private_key or (2) public_key parameter in a T/keyManagement request to plain/settings.html, as demonstrated by uploading a Linux ELF file and a shell script.
- CVSS v2.0
- 6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P - EPSS
- 5.63% chance of exploitation in the next 30 days, 92th percentile
- Published
- 2013-06-28
- Updated
- 2024-09-17