91739vdb entry
http://www.securityfocus.com/bid/91739 CVE-2016-4372
CRITICAL
HPE < 7.2 - Java Deserialization
Record summary
CVE-2016-4372 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.
Description
HPE iMC PLAT before 7.2 E0403P04, iMC EAD before 7.2 E0405P05, iMC APM before 7.2 E0401P04, iMC NTA before 7.2 E0401P01, iMC BIMS before 7.2 E0402P02, and iMC UAM_TAM before 7.2 E0405P05 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBHPE < 7.2 - Java DeserializationExploitDB exploitby Raphael KuhnNot analyzed1 file
References
4h20566.www2.hpe.comConfirmation
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05200601 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2016-4372 42756exploit
https://www.exploit-db.com/exploits/42756