CVE-2016-1998: Input Validation
Published Mar 22, 2016
·Updated
HPE Service Manager (SM) 9.3x before 9.35 P4 and 9.4x before 9.41.P2 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.
Affected Software
8 affected components
hp Service Manager=9.30
hp Service Manager=9.31
hp Service Manager=9.32
hp Service Manager=9.33
hp Service Manager=9.34
hp Service Manager=9.35
hp Service Manager=9.40
hp Service Manager=9.41
Remediation
Event History
Mar 22, 2016
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-1998?
CVE-2016-1998 is categorized as high severity due to its potential for remote command execution.
2
How do I fix CVE-2016-1998?
To fix CVE-2016-1998, upgrade HPE Service Manager to version 9.35 P4 or 9.41 P2 or later.
3
What versions are affected by CVE-2016-1998?
CVE-2016-1998 affects HPE Service Manager versions 9.30 to 9.34, and 9.40 to 9.41 prior to P2.
4
What type of vulnerability is CVE-2016-1998?
CVE-2016-1998 is a remote code execution vulnerability due to issues with a crafted serialized Java object.
5
Who can exploit CVE-2016-1998?
CVE-2016-1998 can be exploited by remote attackers targeting vulnerable instances of HPE Service Manager.