CVE-2016-4372: HP Intelligent Management Center Application Performance Manager

Critical severity, CVSS 9.8. EPSS: 19.4% chance of exploitation in the next 30 days.

HPE iMC PLAT before 7.2 E0403P04, iMC EAD before 7.2 E0405P05, iMC APM before 7.2 E0401P04, iMC NTA before 7.2 E0401P01, iMC BIMS before 7.2 E0402P02, and iMC UAM_TAM before 7.2 E0405P05 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.

Affected products

  • HP Intelligent Management Center Application Performance Manager: up to and including 7.2
  • HP Intelligent Management Center Branch Intelligent Management System: up to and including 7.2
  • HP Intelligent Management Center Endpoint Admission Defense: up to and including 7.2
  • HP Intelligent Management Center Network Traffic Analyzer: up to and including 7.2
  • HP Intelligent Management Center Platform: up to and including 7.2
  • HP Intelligent Management Center User Access Management: up to and including 7.2

Published 2016-07-15. Last modified 2026-06-17.