CVE-2016-2000

Severity CVSS v4.0:
Pending analysis
Type:
CWE-19 Data Handling
Publication date:
05/04/2016
Last modified:
12/04/2025

Description

HPE Asset Manager 9.40, 9.41, and 9.50 and Asset Manager CloudSystem Chargeback 9.40 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hp:asset_manager:9.40:*:*:*:*:*:*:*
cpe:2.3:a:hp:asset_manager:9.41:*:*:*:*:*:*:*
cpe:2.3:a:hp:asset_manager:9.50:*:*:*:*:*:*:*
cpe:2.3:a:hp:asset_manager_cloudsystem_chargeback:9.40:*:*:*:*:*:*:*