A remote code execution vulnerability was identified in HP Business Service Management (BSM) using Apache Commons Collection Java Deserialization versions v9.20-v9.26
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/94183 | third party advisory vdb entry |
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c05327447 | vendor advisory |