Vulnerability Description
HPE iMC PLAT before 7.2 E0403P04, iMC EAD before 7.2 E0405P05, iMC APM before 7.2 E0401P04, iMC NTA before 7.2 E0401P01, iMC BIMS before 7.2 E0402P02, and iMC UAM_TAM before 7.2 E0405P05 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hp | Intelligent Management Center Application Performance Manager | <= 7.2 |
| Hp | Intelligent Management Center Branch Intelligent Management System | <= 7.2 |
| Hp | Intelligent Management Center Endpoint Admission Defense | <= 7.2 |
| Hp | Intelligent Management Center Network Traffic Analyzer | <= 7.2 |
| Hp | Intelligent Management Center Platform | <= 7.2 |
| Hp | Intelligent Management Center User Access Management | <= 7.2 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/91739
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-cVendor Advisory
- https://www.exploit-db.com/exploits/42756/
- http://www.securityfocus.com/bid/91739
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-cVendor Advisory
- https://www.exploit-db.com/exploits/42756/
FAQ
What is CVE-2016-4372?
CVE-2016-4372 is a vulnerability with a CVSS score of 9.8 (CRITICAL). HPE iMC PLAT before 7.2 E0403P04, iMC EAD before 7.2 E0405P05, iMC APM before 7.2 E0401P04, iMC NTA before 7.2 E0401P01, iMC BIMS before 7.2 E0402P02, and iMC UAM_TAM before 7.2 E0405P05 allow remote ...
How severe is CVE-2016-4372?
CVE-2016-4372 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2016-4372?
Check the references section above for vendor advisories and patch information. Affected products include: Hp Intelligent Management Center Application Performance Manager, Hp Intelligent Management Center Branch Intelligent Management System, Hp Intelligent Management Center Endpoint Admission Defense, Hp Intelligent Management Center Network Traffic Analyzer, Hp Intelligent Management Center Platform.