First published: Thu Sep 29 2016(Updated: )
The RMI service in HP Network Automation Software 9.1x, 9.2x, 10.0x before 10.00.02.01, and 10.1x before 10.11.00.01 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) and Commons BeanUtils libraries.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HP Network Automation | =9.10 | |
HP Network Automation | =9.20 | |
HP Network Automation | =9.22 | |
HP Network Automation | =9.22.01 | |
HP Network Automation | =9.22.02 | |
HP Network Automation | =10.00 | |
HP Network Automation | =10.00.01 | |
HP Network Automation | =10.00.02 | |
HP Network Automation | =10.10 | |
HP Network Automation | =10.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-4385 is rated as high severity due to the potential for remote code execution.
To fix CVE-2016-4385, update HP Network Automation Software to version 10.00.02.01 or later, or 10.11.00.01 or later.
CVE-2016-4385 affects users running HP Network Automation Software versions 9.1x, 9.2x, 10.0x before 10.00.02.01, and 10.1x before 10.11.00.01.
CVE-2016-4385 facilitates remote attackers to execute arbitrary commands via crafted serialized Java objects.
CVE-2016-4385 is related to vulnerabilities in the Apache Commons Collections and Commons BeanUtils libraries.