CVE-2016-4369: HP Discovery And Dependency Mapping Inventory

High severity, CVSS 8.8. EPSS: 2.4% chance of exploitation in the next 30 days.

HPE Discovery and Dependency Mapping Inventory (DDMi) 9.30, 9.31, 9.32, 9.32 update 1, 9.32 update 2, and 9.32 update 3 allows remote authenticated users to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.

Affected products

  • HP Discovery And Dependency Mapping Inventory: version 9.30 only; version 9.31 only; version 9.32 only

Published 2016-06-08. Last modified 2026-06-17.