CVE-2016-1995: Critical severity hp system management homepage vulnerability
Published Mar 18, 2016
·Updated
HPE System Management Homepage before 7.5.4 allows remote attackers to execute arbitrary code via unspecified vectors.
Affected Software
1 affected component
HP System Management Homepage<=7.5.3.1
Remediation
Event History
Mar 18, 2016
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-1995?
CVE-2016-1995 is classified as high severity due to its potential to allow remote code execution by attackers.
2
How do I fix CVE-2016-1995?
To mitigate CVE-2016-1995, upgrade HPE System Management Homepage to version 7.5.4 or later.
3
What types of attacks does CVE-2016-1995 enable?
CVE-2016-1995 enables remote attackers to execute arbitrary code on vulnerable systems.
4
Which versions of HPE System Management Homepage are affected by CVE-2016-1995?
Versions of HPE System Management Homepage prior to 7.5.4 are affected by CVE-2016-1995.
5
Is CVE-2016-1995 still a risk if I am using the latest software updates?
If you are using HPE System Management Homepage version 7.5.4 or later, CVE-2016-1995 should not pose a risk.