peter bassill · operator
$ cve CVE-2016-4372 JSON

CVE-2016-4372 EXPLOIT

9.8
CRITICAL · CVSS 3.0 · EPSS 19.4% (pctl 97)

Patch early

A public exploit exists.

Description

HPE iMC PLAT before 7.2 E0403P04, iMC EAD before 7.2 E0405P05, iMC APM before 7.2 E0401P04, iMC NTA before 7.2 E0401P01, iMC BIMS before 7.2 E0402P02, and iMC UAM_TAM before 7.2 E0405P05 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS19.44% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploityes
Published2016-07-15
Last modified2026-06-17

Affected (6)

VendorProduct
hpintelligent management center application performance manager
hpintelligent management center branch intelligent management system
hpintelligent management center endpoint admission defense
hpintelligent management center network traffic analyzer
hpintelligent management center platform
hpintelligent management center user access management

Public exploits

SourceTitleDate
exploit-dbHPE < 7.2 - Java Deserialization2017-09-19

References

→ the Explorer  ·  watch your stack  ·  NVD