CVE-2016-4372

critical HPE
CVSS v3 Base Score
9.8
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
10.2%
Exploitation probability in 30 days
Top 7% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Confidentiality
High
Integrity
High
Availability
High
Published: July 15, 2016 (3590 days ago)
Last Modified: May 6, 2026
Vendor: HPE
Source: NVD

Description

HPE iMC PLAT before 7.2 E0403P04, iMC EAD before 7.2 E0405P05, iMC APM before 7.2 E0401P04, iMC NTA before 7.2 E0401P01, iMC BIMS before 7.2 E0402P02, and iMC UAM_TAM before 7.2 E0405P05 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.

CWE

CWE-20

Affected Products

hp intelligent management center application performance managerhp intelligent management center branch intelligent management systemhp intelligent management center endpoint admission defensehp intelligent management center network traffic analyzerhp intelligent management center platformhp intelligent management center user access management

References