CVE-2016-2000: HP Asset Manager

Critical severity, CVSS 9.8. EPSS: 4.5% chance of exploitation in the next 30 days.

HPE Asset Manager 9.40, 9.41, and 9.50 and Asset Manager CloudSystem Chargeback 9.40 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.

Affected products

  • HP Asset Manager: version 9.40 only; version 9.41 only; version 9.50 only
  • HP Asset Manager Cloudsystem Chargeback: version 9.40 only

Published 2016-04-05. Last modified 2026-06-17.