7.5
CVSSv2

CVE-2016-4368

Published: 08/06/2016 Updated: 10/06/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

HPE Universal CMDB 10.0 up to and including 10.21, Universal CMDB Configuration Manager 10.0 up to and including 10.21, and Universal Discovery 10.0 up to and including 10.21 allow remote malicious users to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.

Vulnerable Product Search on Vulmon Subscribe to Product

hp universal cmbd foundation 10.20

hp universal cmbd foundation 10.11

hp universal cmbd foundation 10.10

hp universal cmbd foundation 10.01

hp universal cmbd foundation 10.0

hp universal cmbd foundation 10.21

hp universal cmbd configuration manager 10.10

hp universal cmbd configuration manager 10.11

hp universal cmbd configuration manager 10.20

hp universal cmbd configuration manager 10.21

hp universal cmbd configuration manager 10.01

hp universal cmbd configuration manager 10.0

hp universal discovery 10.11

hp universal discovery 10.20

hp universal discovery 10.21

hp universal discovery 10.01

hp universal discovery 10.0

hp universal discovery 10.10