ZeroHour

CVE-2016-4368

CVSS 3.0
9.8 critical
EPSS
5%p91
Published
()
Modified
Description

HPE Universal CMDB 10.0 through 10.21, Universal CMDB Configuration Manager 10.0 through 10.21, and Universal Discovery 10.0 through 10.21 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.

Vendors
hp
Products
universal cmbd foundation, universal cmbd configuration manager, universal discovery
Weakness
CWE-20
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.