Vulnerability record · CVE-2013-4812 · published 16 September 2013
CVE-2013-4812: HP ProCurve Manager SNAC servlet file upload leads to RCE
Hp · Identity Driven Manager
UpdateCertificatesServlet in the SNAC registration server of HP ProCurve Manager (PCM) 3.20/4.0, PCM+ 3.20/4.0, and Identity Driven Manager 4.0 fails to validate the fileName argument. This lets a remote attacker upload .jsp files and execute arbitrary code on the server. The flaw is a classic improper input validation issue in a network-exposed component.
Description
UpdateCertificatesServlet in the SNAC registration server in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity Driven Manager (IDM) 4.0 does not properly validate the fileName argument, which allows remote attackers to upload .jsp files and consequently execute arbitrary code via unspecified vectors, aka ZDI-CAN-1743.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 score of 10 with network, no-auth, complete impact, and a high EPSS percentile make this a top-priority remote code execution flaw.
What it is
UpdateCertificatesServlet in the SNAC registration server of HP ProCurve Manager (PCM) 3.20/4.0, PCM+ 3.20/4.0, and Identity Driven Manager 4.0 fails to validate the fileName argument. This lets a remote attacker upload .jsp files and execute arbitrary code on the server. The flaw is a classic improper input validation issue in a network-exposed component.
Impact
An unauthenticated remote attacker can upload and execute arbitrary JSP code, gaining full control of the affected server. This compromises confidentiality, integrity, and availability of the host and any data it manages.
Attack surface
Reachable over the network via the SNAC registration server's UpdateCertificatesServlet; the CVSS vector (AV:N/AC:L/Au:N) indicates no authentication or user interaction is required. The description does not specify the exact port or protocol beyond the servlet endpoint.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented. EPSS shows a 30-day probability of 0.51903 (98.9th percentile), indicating high predicted exploitation activity, though no public exploit details are provided in the record.
What to do
- Apply the HP vendor advisory patch for PCM/PCM+/IDM as soon as possible.
- Restrict network access to the SNAC registration server to trusted management hosts only.
- Disable or remove the UpdateCertificatesServlet if it is not required for operations.
- Enforce strict file-type and filename validation on any upload endpoint, rejecting executable extensions such as .jsp.
- Monitor the server for unexpected .jsp files or outbound connections from the management host.
Detection
- Search web server logs for POST requests to UpdateCertificatesServlet with filenames ending in .jsp.
- Monitor the filesystem for newly created .jsp files in web-accessible directories on PCM/IDM hosts.
- Alert on unexpected child processes spawned by the Java/web server process on these systems.
- Review network traffic for uploads to the SNAC registration server from untrusted sources.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2013-4812 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-4812), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.