CVE-2016-4368

HPE Universal CMDB 10.0 through 10.21, Universal CMDB Configuration Manager 10.0 through 10.21, and Universal Discovery 10.0 through 10.21 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 68%
VendorProductVersion
hpuniversal_cmbd_foundation
10.0
hpuniversal_cmbd_foundation
10.01
hpuniversal_cmbd_foundation
10.10
hpuniversal_cmbd_foundation
10.11
hpuniversal_cmbd_foundation
10.20
hpuniversal_cmbd_foundation
10.21
hpuniversal_cmbd_configuration_manager
10.0
hpuniversal_cmbd_configuration_manager
10.01
hpuniversal_cmbd_configuration_manager
10.10
hpuniversal_cmbd_configuration_manager
10.11
hpuniversal_cmbd_configuration_manager
10.20
hpuniversal_cmbd_configuration_manager
10.21
hpuniversal_discovery
10.0
hpuniversal_discovery
10.01
hpuniversal_discovery
10.10
hpuniversal_discovery
10.11
hpuniversal_discovery
10.20
hpuniversal_discovery
10.21
𝑥
= Vulnerable software versions