CVE-2016-4405: HP Business Service Management

High severity, CVSS 8.8. EPSS: 4.8% chance of exploitation in the next 30 days.

A remote code execution vulnerability was identified in HP Business Service Management (BSM) using Apache Commons Collection Java Deserialization versions v9.20-v9.26

Affected products

  • HP Business Service Management: from 9.20, up to and including 9.26

Published 2018-08-06. Last modified 2026-06-17.