CVE-2016-4373: Critical severity micro focus operations manager i vulnerability
The AdminUI in HPE Operations Manager (OM) before 9.21.130 on Linux, Unix, and Solaris allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-4373?
CVE-2016-4373 is considered critical due to its potential for remote command execution.
How do I fix CVE-2016-4373?
To fix CVE-2016-4373, you should upgrade HPE Operations Manager to version 9.21.130 or later.
What versions of HPE Operations Manager are affected by CVE-2016-4373?
CVE-2016-4373 affects HPE Operations Manager versions 9.21.120 and earlier on Linux, Unix, and Solaris.
Can CVE-2016-4373 be exploited remotely?
Yes, CVE-2016-4373 can be exploited by remote attackers to execute arbitrary commands.
What is the cause of CVE-2016-4373?
CVE-2016-4373 is caused by vulnerabilities in the AdminUI related to improper handling of a crafted serialized Java object in the Apache Commons Collections library.