CRITICAL · 9.8

CVE-2016-4372

HPE iMC PLAT before 7.2 E0403P04, iMC EAD before 7.2 E0405P05, iMC APM before 7.2 E0401P04, iMC NTA before 7.2 E0401P01, iMC BIMS before 7.2 E0402P02, and iMC UAM_TAM before 7.2 E0405P05 allow remote ...

Vulnerability Description

HPE iMC PLAT before 7.2 E0403P04, iMC EAD before 7.2 E0405P05, iMC APM before 7.2 E0401P04, iMC NTA before 7.2 E0401P01, iMC BIMS before 7.2 E0402P02, and iMC UAM_TAM before 7.2 E0405P05 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.

CVSS Score

9.8

CRITICAL

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
HpIntelligent Management Center Application Performance Manager<= 7.2
HpIntelligent Management Center Branch Intelligent Management System<= 7.2
HpIntelligent Management Center Endpoint Admission Defense<= 7.2
HpIntelligent Management Center Network Traffic Analyzer<= 7.2
HpIntelligent Management Center Platform<= 7.2
HpIntelligent Management Center User Access Management<= 7.2

Related Weaknesses (CWE)

References

FAQ

What is CVE-2016-4372?

CVE-2016-4372 is a vulnerability with a CVSS score of 9.8 (CRITICAL). HPE iMC PLAT before 7.2 E0403P04, iMC EAD before 7.2 E0405P05, iMC APM before 7.2 E0401P04, iMC NTA before 7.2 E0401P01, iMC BIMS before 7.2 E0402P02, and iMC UAM_TAM before 7.2 E0405P05 allow remote ...

How severe is CVE-2016-4372?

CVE-2016-4372 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2016-4372?

Check the references section above for vendor advisories and patch information. Affected products include: Hp Intelligent Management Center Application Performance Manager, Hp Intelligent Management Center Branch Intelligent Management System, Hp Intelligent Management Center Endpoint Admission Defense, Hp Intelligent Management Center Network Traffic Analyzer, Hp Intelligent Management Center Platform.