CVE-2016-2009: High severity hp network node manager i vulnerability
HPE Network Node Manager i (NNMi) 9.20, 9.23, 9.24, 9.25, 10.00, and 10.01 allows remote authenticated users to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2009?
CVE-2016-2009 has been classified as a critical severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2016-2009?
To fix CVE-2016-2009, upgrade HPE Network Node Manager i to the latest version where the vulnerability has been patched.
Who is affected by CVE-2016-2009?
CVE-2016-2009 affects remote authenticated users of HPE Network Node Manager i versions 9.20, 9.23, 9.24, 9.25, 10.00, and 10.01.
What type of vulnerability is CVE-2016-2009?
CVE-2016-2009 is a remote code execution vulnerability caused by a flaw in the handling of serialized Java objects.
Can CVE-2016-2009 be exploited without authentication?
No, CVE-2016-2009 requires remote authenticated access to exploit the vulnerability.