CVE-2016-1985: Code Injection
Published Jan 30, 2016
·Updated
HPE Operations Manager 8.x and 9.0 on Windows allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.
Affected Software
5 affected components
HP Operations Manager=8.1
HP Operations Manager=8.10
HP Operations Manager=8.16
HP Operations Manager=9.0
Microsoft Windows
Remediation
Event History
Jan 30, 2016
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-1985?
CVE-2016-1985 is classified as a critical vulnerability due to its potential for remote command execution.
2
How do I fix CVE-2016-1985?
To fix CVE-2016-1985, update to the latest versions of HPE Operations Manager that have patched this vulnerability.
3
Who is affected by CVE-2016-1985?
CVE-2016-1985 affects HPE Operations Manager versions 8.1, 8.10, 8.16, and 9.0 running on Windows.
4
What are the potential impacts of CVE-2016-1985?
The potential impacts of CVE-2016-1985 include unauthorized remote command execution leading to system compromise.
5
What causes CVE-2016-1985?
CVE-2016-1985 is caused by improper handling of serialized Java objects in the Apache Commons Collections library.