← Vulnerability feed

Vulnerability record · CVE-2016-1997 · published 22 March 2016

CVE-2016-1997: Hp operations orchestration improper input validation vulnerability

Hp · Operations Orchestration

HPE Operations Orchestration 10.x before 10.51 and Operations Orchestration content before 1.7.0 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.

9.8 CVSS 3.0 Critical EPSS 6.7% · top 6.3% CWE-20 · Improper input validation
9.8CVSS 3.0 base score, v2 10.0
6.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

HPE Operations Orchestration 10.x before 10.51 and Operations Orchestration content before 1.7.0 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-1997 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2012-3258Hp operations orchestration vulnerabilityUnspecified vulnerability in HP Operations Orchestration 9.0 before 9.03 allows remote attackers to execute arbitrary code via unknown vectors.EPSS 9.9%9.8CVE-2016-8519Hp operations orchestration deserialization of untrusted data vulnerabilityA remote code execution vulnerability in HPE Operations Orchestration Community edition and Enterprise edition prior to v10.70 was found.EPSS 28%9.8CVE-2017-8994Hp operations orchestration improper input validation vulnerabilityA input validation vulnerability in HPE Operations Orchestration product all versions prior to 10.80, allows for the execution of code remotely.EPSS 9.8%7.5CVE-2018-6490Hp operations orchestration improper input validation vulnerabilityDenial of Service vulnerability in Micro Focus Operations Orchestration Software, version 10.x. This vulnerability could be remotely exploited to all…EPSS 2.6%7.5CVE-2015-2109Hp operations orchestration vulnerabilityUnspecified vulnerability in HP Operations Orchestration 10.x allows remote attackers to bypass authentication, and obtain sensitive information or m…EPSS 4.1%6.8CVE-2015-5451Hp operations orchestration cross-site request forgery vulnerabilityCross-site request forgery (CSRF) vulnerability in HP Operations Orchestration Central 10.x before 10.22.001 allows remote attackers to hijack the au…EPSS 1.5%6.8CVE-2013-6192Hp operations orchestration cross-site request forgery vulnerabilityCross-site request forgery (CSRF) vulnerability in HP Operations Orchestration before 9 allows remote attackers to hijack the authentication of unspe…EPSS 0.97%4.3CVE-2013-6191Hp operations orchestration cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in HP Operations Orchestration before 9 allows remote attackers to inject arbitrary web script or HTML via u…EPSS 2.5%

Source: NIST National Vulnerability Database (record CVE-2016-1997), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.