CVE-2016-1998: HP Service Manager

Critical severity, CVSS 9.8. EPSS: 6.8% chance of exploitation in the next 30 days.

HPE Service Manager (SM) 9.3x before 9.35 P4 and 9.4x before 9.41.P2 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.

Affected products

  • HP Service Manager: version 9.30 only; version 9.31 only; version 9.32 only; version 9.33 only; version 9.34 only; version 9.35 only; …

Published 2016-03-22. Last modified 2026-06-17.