CVE-2013-4836 describes an unspecified vulnerability in the GossipService SOAP Request implementation within the Synchronizer component of HP Application LifeCycle Management (ALM) versions prior to 1.4.2. This critical flaw allows unauthenticated remote attackers to execute arbitrary code via unknown vectors. With a CVSS score of 7.5, it presents a high severity risk due to its network-based attack vector, low attack complexity, and potential for partial confidentiality, integrity, and availability impact. While no public exploit code, Metasploit modules, or Nuclei templates are available, and there is no evidence of active exploitation or significant community discussion, the potential for remote code execution warrants attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.41CPE matchmatch criteria | cpe:2.3:a:hp:alm_synchronizer:*:*:*:*:*:*:*:* | ||
1.10CPE matchmatch criteria | cpe:2.3:a:hp:alm_synchronizer:1.10:*:*:*:*:*:*:* | ||
1.20CPE matchmatch criteria | cpe:2.3:a:hp:alm_synchronizer:1.20:*:*:*:*:*:*:* | ||
1.30CPE matchmatch criteria | cpe:2.3:a:hp:alm_synchronizer:1.30:*:*:*:*:*:*:* | ||
1.40CPE matchmatch criteria | cpe:2.3:a:hp:alm_synchronizer:1.40:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.