First published: Fri Jul 15 2016(Updated: )
HPE iMC PLAT before 7.2 E0403P04, iMC EAD before 7.2 E0405P05, iMC APM before 7.2 E0401P04, iMC NTA before 7.2 E0401P01, iMC BIMS before 7.2 E0402P02, and iMC UAM_TAM before 7.2 E0405P05 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Hp Intelligent Management Center Application Performance Manager | <=7.2 | |
Hp Intelligent Management Center Branch Intelligent Management System | <=7.2 | |
Hp Intelligent Management Center Endpoint Admission Defense | <=7.2 | |
Hp Intelligent Management Center Network Traffic Analyzer | <=7.2 | |
HP Intelligent Management Center | <=7.2 | |
Hp Intelligent Management Center User Access Management | <=7.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-4372 has a high severity rating due to its ability to allow remote attackers to execute arbitrary commands.
To fix CVE-2016-4372, you should update your affected HPE Intelligent Management Center software to the latest version that resolves the vulnerability.
CVE-2016-4372 affects several versions of HPE Intelligent Management Center components, including Application Performance Manager, Endpoint Admission Defense, and Network Traffic Analyzer before version 7.2 E0405P05.
CVE-2016-4372 is classified as a remote command execution vulnerability caused by processing crafted serialized Java objects.
CVE-2016-4372 was disclosed in 2016 and impacts various versions of HPE iMC software prior to updates released in 2017.