The RMI service in HP Network Automation Software 9.1x, 9.2x, 10.0x before 10.00.02.01, and 10.1x before 10.11.00.01 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) and Commons BeanUtils libraries.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Network_automation | Hp | 9.10 (including) | 9.10 (including) |
Network_automation | Hp | 9.20 (including) | 9.20 (including) |
Network_automation | Hp | 9.22 (including) | 9.22 (including) |
Network_automation | Hp | 9.22.01 (including) | 9.22.01 (including) |
Network_automation | Hp | 9.22.02 (including) | 9.22.02 (including) |
Network_automation | Hp | 10.00 (including) | 10.00 (including) |
Network_automation | Hp | 10.00.01 (including) | 10.00.01 (including) |
Network_automation | Hp | 10.00.02 (including) | 10.00.02 (including) |
Network_automation | Hp | 10.10 (including) | 10.10 (including) |
Network_automation | Hp | 10.11 (including) | 10.11 (including) |