HPE Universal CMDB 10.0 through 10.21, Universal CMDB Configuration Manager 10.0 through 10.21, and Universal Discovery 10.0 through 10.21 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.
| Software | From | Fixed in |
|---|---|---|
| hp / universal_cmbd_foundation | 10.21 | 10.21.x |
| hp / universal_cmbd_foundation | 10.01 | 10.01.x |
| hp / universal_cmbd_foundation | 10.0 | 10.0.x |
| hp / universal_cmbd_foundation | 10.20 | 10.20.x |
| hp / universal_cmbd_foundation | 10.11 | 10.11.x |
| hp / universal_cmbd_foundation | 10.10 | 10.10.x |
| hp / universal_cmbd_configuration_manager | 10.10 | 10.10.x |
| hp / universal_cmbd_configuration_manager | 10.11 | 10.11.x |
| hp / universal_cmbd_configuration_manager | 10.20 | 10.20.x |
| hp / universal_cmbd_configuration_manager | 10.0 | 10.0.x |
| hp / universal_cmbd_configuration_manager | 10.21 | 10.21.x |
| hp / universal_cmbd_configuration_manager | 10.01 | 10.01.x |
| hp / universal_discovery | 10.10 | 10.10.x |
| hp / universal_discovery | 10.0 | 10.0.x |
| hp / universal_discovery | 10.21 | 10.21.x |
| hp / universal_discovery | 10.11 | 10.11.x |
| hp / universal_discovery | 10.20 | 10.20.x |
| hp / universal_discovery | 10.01 | 10.01.x |