Vulnerabilities > CVE-2014-2612 - Information Disclosure vulnerability in HP Release Control

047910
CVSS 4.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
hp
linux
microsoft
exploit available

Summary

Unspecified vulnerability in HP Release Control 9.x before 9.13 p3 and 9.2x before RC 9.21.0003 p1 on Windows and 9.2x before RC 9.21.0002 p1 on Linux allows remote authenticated users to obtain sensitive information via unknown vectors.

Exploit-Db

descriptionHP Release Control Authenticated XXE. CVE-2014-2612. Webapps exploit for windows platform
idEDB-ID:33434
last seen2016-02-03
modified2014-05-19
published2014-05-19
reporterBrandon Perry
sourcehttps://www.exploit-db.com/download/33434/
titleHP Release Control Authenticated XXE

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/126703/hp-xxe.rb.txt
idPACKETSTORM:126703
last seen2016-12-05
published2014-05-19
reporterBrandon Perry
sourcehttps://packetstormsecurity.com/files/126703/HP-Release-Control-9.20.0000-Build-395-XXE.html
titleHP Release Control 9.20.0000 Build 395 XXE