← Back to CVE List
Vulnerability Intelligence Report

CVE-2016-1998

HPE Service Manager (SM) 9.3x before 9.35 P4 and 9.4x before 9.41.P2 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.

No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
EPSS Probability:6.69%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
hp service_manager 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
6.689%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2016-01-22T00:00:00
Published2016-03-22T10:00:00
Patch Date2016-03-21
Last Updated2024-08-05T23:17:49

LINK COPIED TO CLIPBOARD