CVE-2016-1997: HP Operations Orchestration
Critical severity, CVSS 9.8. EPSS: 6.7% chance of exploitation in the next 30 days.
HPE Operations Orchestration 10.x before 10.51 and Operations Orchestration content before 1.7.0 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.
Affected products
- HP Operations Orchestration: version 10.0 only; version 10.01 only; version 10.02 only; version 10.10 only; version 10.20 only; version 10.21 only; …
- HP Operations Orchestration Content: up to and including 1.5.3
Published 2016-03-22. Last modified 2026-06-17.