CVE-2017-12500
HIGHHPE Intelligent Management Center PLAT 7.3 (E0504) - Remote Code Execution
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-12500. PoCs published by TrendyTofu.
AI-analyzed exploit summary This Metasploit module exploits an expression language injection vulnerability (CVE-2017-8982) combined with an authentication bypass (CVE-2017-12500) in HPE iMC before 7.3 E0504P04. It achieves unauthenticated remote code execution by injecting malicious EL expressions via the `beanName` parameter.
Description
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.
Exploits (1)
This Metasploit module exploits an expression language injection vulnerability (CVE-2017-8982) combined with an authentication bypass (CVE-2017-12500) in HPE iMC before 7.3 E0504P04. It achieves unauthenticated remote code execution by injecting malicious EL expressions via the `beanName` parameter.
References (4)
Scores
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H