CVE-2016-4373
HP Security Bulletin HPSBGN03630 1
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The AdminUI in HPE Operations Manager (OM) before 9.21.130 on Linux, Unix, and Solaris allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.
El AdminUI en HPE Operations Manager (OM) en versiones anteriores a 9.21.130 en Linux, Unix y Solaris permite a atacantes remotos ejecutar comandos arbitrarios a través de un objeto Java serializado manipulado, relacionado con la librería Apache Commons Collections (ACC).
A vulnerability in Apache Commons Collections (ACC) for handling Java object deserialization was addressed in the AdminUI of HP Operations Manager for Unix, Solaris and Linux. The vulnerability could be exploited remotely to allow remote code execution. Revision 1 of this advisory.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-04-29 CVE Reserved
- 2016-07-26 CVE Published
- 2024-08-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-284: Improper Access Control
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/92122 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05206507 | 2016-11-28 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Hp Search vendor "Hp" | Operations Manager Search vendor "Hp" for product "Operations Manager" | <= 9.21.120 Search vendor "Hp" for product "Operations Manager" and version " <= 9.21.120" | linux |
Affected
| ||||||
Hp Search vendor "Hp" | Operations Manager Search vendor "Hp" for product "Operations Manager" | <= 9.21.120 Search vendor "Hp" for product "Operations Manager" and version " <= 9.21.120" | solaris |
Affected
| ||||||
Hp Search vendor "Hp" | Operations Manager Search vendor "Hp" for product "Operations Manager" | <= 9.21.120 Search vendor "Hp" for product "Operations Manager" and version " <= 9.21.120" | unix |
Affected
| ||||||
Hp Search vendor "Hp" | Operations Manager Search vendor "Hp" for product "Operations Manager" | 9.20.0 Search vendor "Hp" for product "Operations Manager" and version "9.20.0" | linux |
Affected
| ||||||
Hp Search vendor "Hp" | Operations Manager Search vendor "Hp" for product "Operations Manager" | 9.20.0 Search vendor "Hp" for product "Operations Manager" and version "9.20.0" | solaris |
Affected
| ||||||
Hp Search vendor "Hp" | Operations Manager Search vendor "Hp" for product "Operations Manager" | 9.20.0 Search vendor "Hp" for product "Operations Manager" and version "9.20.0" | unix |
Affected
|