CVE-2013-4810

CRITICAL KEV RANSOMWARE

HP ProCurve Manager and Application Lifecycle Management - Remote Code Execution via Marshalled Object

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2013-4810 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added March 25, 2022, with confirmed use in ransomware campaigns. EIP tracks 1 public exploit from researchers including rgod.

AI-analyzed exploit summary This PHP script exploits CVE-2013-4810, a deserialization vulnerability in Apache Tomcat/JBoss EJBInvokerServlet and JMXInvokerServlet, to achieve remote code execution. It crafts a malicious serialized object to deploy a JSP shell and then executes arbitrary commands via HTTP requests.

Description

HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, Identity Driven Manager (IDM) 4.0, and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to (1) EJBInvokerServlet or (2) JMXInvokerServlet, aka ZDI-CAN-1760. NOTE: this is probably a duplicate of CVE-2007-1036, CVE-2010-0738, and/or CVE-2012-0874.

Exploits (1)

exploitdb WORKING POC VERIFIED
by rgod · phpremotephp
https://www.exploit-db.com/exploits/28713

This PHP script exploits CVE-2013-4810, a deserialization vulnerability in Apache Tomcat/JBoss EJBInvokerServlet and JMXInvokerServlet, to achieve remote code execution. It crafts a malicious serialized object to deploy a JSP shell and then executes arbitrary commands via HTTP requests.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Apache Tomcat/JBoss (EJBInvokerServlet/JMXInvokerServlet), McAfee Web Reporter 5.2.1
No auth needed
Prerequisites: Target must have exposed EJBInvokerServlet or JMXInvokerServlet · Network access to the target server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/28713/
Third Party Advisory, VDB Entry x_refsource_misc
http://zerodayinitiative.com/advisories/ZDI-13-229/
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=143039425503668&w=2
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1029010
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=138696448823753&w=2
Broken Link, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/54788

Scores

CVSS v3 9.8
EPSS 0.8970
EPSS Percentile 99.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable yes
Technical Impact total

Details

CISA KEV 2022-03-25
VulnCheck KEV 2016-03-25
InTheWild.io 2022-03-25
ENISA EUVD EUVD-2013-4655
Ransomware Use Confirmed
CWE
CWE-94
Status published
Products (3)
hp/application_lifecycle_management
hp/procurve_manager 3.20 (2 CPE variants)
hp/procurve_manager 4.0 (2 CPE variants)
Published Sep 16, 2013
KEV Added Mar 25, 2022
Tracked Since Feb 18, 2026