Remote Command Execution Vulnerability in HPE Operations Manager Software
CVE-2016-1985

10CRITICAL

Key Information:

Vendor
HP
Vendor
CVE Published:
30 January 2016

Summary

A vulnerability in HPE Operations Manager 8.x and 9.0 on Windows allows remote attackers to execute arbitrary commands by leveraging a crafted serialized Java object. This issue is associated with the Apache Commons Collections library, which plays a crucial role in the deserialization process. Exploiting this vulnerability can lead to unauthorized command execution and potential takeover of the affected systems. It is important for users to apply the necessary patches or updates to safeguard against this threat.

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.