CVE-2016-4372 EXPLOIT
9.8
CRITICAL · CVSS 3.0 · EPSS 19.4% (pctl 97)
Patch early
A public exploit exists.
Description
HPE iMC PLAT before 7.2 E0403P04, iMC EAD before 7.2 E0405P05, iMC APM before 7.2 E0401P04, iMC NTA before 7.2 E0401P01, iMC BIMS before 7.2 E0402P02, and iMC UAM_TAM before 7.2 E0405P05 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 19.44% — more likely to be exploited than 97% of all CVEs |
| Weakness | CWE-20 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2016-07-15 |
| Last modified | 2026-06-17 |
Affected (6)
| Vendor | Product |
|---|---|
| hp | intelligent management center application performance manager |
| hp | intelligent management center branch intelligent management system |
| hp | intelligent management center endpoint admission defense |
| hp | intelligent management center network traffic analyzer |
| hp | intelligent management center platform |
| hp | intelligent management center user access management |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | HPE < 7.2 - Java Deserialization | 2017-09-19 |
References
- http://www.securityfocus.com/bid/91739
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05200601
- https://www.exploit-db.com/exploits/42756/
- http://www.securityfocus.com/bid/91739
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05200601
- https://www.exploit-db.com/exploits/42756/
→ the Explorer · watch your stack · NVD