CVE-2016-1997

HPE Operations Orchestration 10.x before 10.51 and Operations Orchestration content before 1.7.0 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 84%
VendorProductVersion
hpoperations_orchestration
10.0
hpoperations_orchestration
10.01
hpoperations_orchestration
10.02
hpoperations_orchestration
10.10
hpoperations_orchestration
10.20
hpoperations_orchestration
10.21
hpoperations_orchestration
10.22
hpoperations_orchestration
10.22.1
hpoperations_orchestration
10.50
hpoperations_orchestration_content
𝑥
≤ 1.5.3
𝑥
= Vulnerable software versions