Arbitrary Command Execution via Serialized Java Object in HPE Universal CMDB and Universal Discovery

Arbitrary Command Execution via Serialized Java Object in HPE Universal CMDB and Universal Discovery

CVE-2016-4368 · HIGH Severity

AV:N/AC:L/AU:N/C:P/I:P/A:P

HPE Universal CMDB 10.0 through 10.21, Universal CMDB Configuration Manager 10.0 through 10.21, and Universal Discovery 10.0 through 10.21 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.

Learn more about our Cis Benchmark Audit For Apache Http Server.