CVE-2014-2609

HP Executive Scorecard <9.42 - RCE

Title source: llm

Description

The Java Glassfish Admin Console in HP Executive Scorecard 9.40 and 9.41 does not require authentication, which allows remote attackers to execute arbitrary code via a session on TCP port 10001, aka ZDI-CAN-2116.

Scores

EPSS 0.2505
EPSS Percentile 96.1%

Classification

CWE
CWE-287
Status draft

Affected Products (2)

hp/executive_scorecard
hp/executive_scorecard

Timeline

Published Jun 19, 2014
Tracked Since Feb 18, 2026