First published: Wed Jun 08 2016(Updated: )
HPE Universal CMDB 10.0 through 10.21, Universal CMDB Configuration Manager 10.0 through 10.21, and Universal Discovery 10.0 through 10.21 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HP Universal CMDB Foundation | =10.0 | |
HP Universal CMDB Foundation | =10.01 | |
HP Universal CMDB Foundation | =10.10 | |
HP Universal CMDB Foundation | =10.11 | |
HP Universal CMDB Foundation | =10.20 | |
HP Universal CMDB Foundation | =10.21 | |
HP Universal Configuration Management Database | =10.0 | |
HP Universal Configuration Management Database | =10.01 | |
HP Universal Configuration Management Database | =10.10 | |
HP Universal Configuration Management Database | =10.11 | |
HP Universal Configuration Management Database | =10.20 | |
HP Universal Configuration Management Database | =10.21 | |
HP Universal Discovery | =10.0 | |
HP Universal Discovery | =10.01 | |
HP Universal Discovery | =10.10 | |
HP Universal Discovery | =10.11 | |
HP Universal Discovery | =10.20 | |
HP Universal Discovery | =10.21 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-4368 has a critical severity rating due to its potential for remote code execution.
To fix CVE-2016-4368, update the affected software to the latest version provided by HPE that addresses this vulnerability.
CVE-2016-4368 affects HPE Universal CMDB versions 10.0 through 10.21, Universal CMDB Configuration Manager 10.0 through 10.21, and Universal Discovery 10.0 through 10.21.
Attackers can execute arbitrary commands on the server via a crafted serialized Java object due to CVE-2016-4368.
Yes, CVE-2016-4368 is considered easily exploitable, making it a high-risk vulnerability.