CVE-2013-4835: HP Sitescope

High severity, CVSS 7.5. EPSS: 71% chance of exploitation in the next 30 days.

The APISiteScopeImpl SOAP service in HP SiteScope 10.1x and 11.x before 11.22 allows remote attackers to bypass authentication and execute arbitrary code via a direct request to the issueSiebelCmd method, aka ZDI-CAN-1765.

Affected products

  • HP Sitescope: version 10.11 only; version 10.13 only; version 11.01 only; version 11.1 only; version 11.10 only; version 11.11 only; …

Published 2013-11-04. Last modified 2026-06-16.