CVE-2012-2561: HP Business Service Management

High severity, CVSS 10.0. EPSS: 8.6% chance of exploitation in the next 30 days.

HP Business Service Management (BSM) 9.12 does not properly restrict the uploading of .war files, which allows remote attackers to execute arbitrary JSP code within the JBOSS Application Server component via a crafted request to TCP port 1098, 1099, or 4444.

Affected products

  • HP Business Service Management: version 9.12 only

Published 2012-05-21. Last modified 2026-06-16.