← All CVEs

CVE-2016-4372

critical · 9.8

HPE iMC PLAT before 7.2 E0403P04, iMC EAD before 7.2 E0405P05, iMC APM before 7.2 E0401P04, iMC NTA before 7.2 E0401P01, iMC BIMS before 7.2 E0402P02, and iMC UAM_TAM before 7.2 E0405P05 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.

9.8
CVSS
19.4%
EPSS (exploit prob.)
97th
EPSS percentile
2016-07-15
Published

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-20

Affected products

VendorProductAffected versions
hpintelligent_management_center_application_performance_manager<= 7.2
hpintelligent_management_center_branch_intelligent_management_system<= 7.2
hpintelligent_management_center_endpoint_admission_defense<= 7.2
hpintelligent_management_center_network_traffic_analyzer<= 7.2
hpintelligent_management_center_platform<= 7.2
hpintelligent_management_center_user_access_management<= 7.2

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2016-4372