Unauthenticated Remote Code Execution in HP TippingPoint Security Management System (SMS) and TippingPoint Virtual Security Management System (vSMS)

Unauthenticated Remote Code Execution in HP TippingPoint Security Management System (SMS) and TippingPoint Virtual Security Management System (vSMS)

CVE-2015-2117 · HIGH Severity

AV:N/AC:L/AU:N/C:P/I:P/A:P

HP TippingPoint Security Management System (SMS) and TippingPoint Virtual Security Management System (vSMS) before 4.1 patch 3 and 4.2 before patch 1 do not require authentication for JBoss RMI requests, which allows remote attackers to execute arbitrary code by (1) uploading this code within an archive or (2) instantiating a class.

Learn more about our Web Application Penetration Testing UK.