PT-2016-4955 · Hewlett Packard+1 · Hpe Xp P9000 Command View Advanced Edition+2
Published
2016-04-20
·
Updated
2016-12-01
·
CVE-2016-2003
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
HPE P9000 Command View Advanced Edition Software (CVAE) versions 7.x through 8.x before 8.4.0-00
XP7 CVAE versions 7.x through 8.x before 8.4.0-00
Description
The issue allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.
Recommendations
For HPE P9000 Command View Advanced Edition Software (CVAE) versions 7.x through 8.x before 8.4.0-00, update to version 8.4.0-00 or later.
For XP7 CVAE versions 7.x through 8.x before 8.4.0-00, update to version 8.4.0-00 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Commons Collections
Hpe Xp P9000 Command View Advanced Edition
Xp7 Cvae