CVE-2016-1998

CRITICAL

HPE Service Manager <9.35 P4-9.41.P2 - Command Injection

Title source: llm
STIX 2.1

Description

HPE Service Manager (SM) 9.3x before 9.35 P4 and 9.4x before 9.41.P2 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.0167
EPSS Percentile 82.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-20
Status published
Products (8)
hp/service_manager 9.30
hp/service_manager 9.31
hp/service_manager 9.32
hp/service_manager 9.33
hp/service_manager 9.34
hp/service_manager 9.35
hp/service_manager 9.40
hp/service_manager 9.41
Published Mar 22, 2016
Tracked Since Feb 18, 2026