9.8
CVSSv3

CVE-2016-3642

Published: 17/06/2016 Updated: 20/06/2016
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 892
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The RMI service in SolarWinds Virtualization Manager 6.3.1 and previous versions allows remote malicious users to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.

Vulnerable Product Search on Vulmon Subscribe to Product

solarwinds virtualization manager

Exploits

Solarwinds Virtualization Manager versions 631 and below suffer from a java deserialization vulnerability ...