CVE-2016-1997: Input Validation
HPE Operations Orchestration 10.x before 10.51 and Operations Orchestration content before 1.7.0 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1997?
CVE-2016-1997 is classified as high severity due to the potential for remote command execution by an attacker.
How do I fix CVE-2016-1997?
To fix CVE-2016-1997, upgrade HPE Operations Orchestration to version 10.51 or later and Operations Orchestration content to version 1.7.0 or later.
What software versions are affected by CVE-2016-1997?
CVE-2016-1997 affects HPE Operations Orchestration versions 10.0 through 10.50 and Operations Orchestration content versions up to 1.5.3.
Can CVE-2016-1997 be exploited remotely?
Yes, CVE-2016-1997 can be exploited remotely, allowing attackers to execute arbitrary commands.
What library is associated with CVE-2016-1997?
CVE-2016-1997 is related to a vulnerability in the Apache Commons Collections library.