CVE-2016-2021Deserialization of Untrusted Data in HP Systems Insight Manager

Severity
8.1HIGHNVD
EPSS
0.3%
top 49.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 8
Latest updateJul 30

Description

HPE Systems Insight Manager (SIM) before 7.5.1 allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors, a different vulnerability than CVE-2016-2017, CVE-2016-2019, CVE-2016-2020, CVE-2016-2022, and CVE-2016-2030.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:NExploitability: 2.8 | Impact: 5.2

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-492h-x276-h4v7: HPE Systems Insight Manager (SIM) before 72022-05-17
CVEList
CVE-2016-2021: HPE Systems Insight Manager (SIM) before 72016-06-08

💥Exploits & PoCs

1
Metasploit
Microsoft Exchange ProxyLogon Collector

🔍Detection Rules

1
Elastic
Microsoft Exchange Server UM Spawning Suspicious Processes

📋Vendor Advisories

8
Oracle
Oracle Oracle Insurance Applications Risk Matrix: Development tools (Apache Commons FileUpload) — CVE-2016-10000312021-10-15
Red Hat
7: Incomplete fix of CVE-2016-4978 in HornetQ library2021-10-05
Red Hat
libzapojit: missing TLS certificate verification2021-08-22
Drupal
Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2021-0032021-05-26
Oracle
Oracle Oracle Siebel CRM Risk Matrix: UIF Open UI (jQuery UI) — CVE-2016-71032021-04-15

🕵️Threat Intelligence

3
Bleepingcomputer
UK govt links 2021 Electoral Commission breach to Exchange server2024-07-30
Securelist
MysterySnail attacks with Windows zero-day2021-10-12
Trendmicro
FormBook Adds Latest Office 365 0-Day Vulnerability CVE-2021-40444 to Its Arsenal2021-09-29
CVE-2016-2021 — Deserialization of Untrusted Data in HP | cvebase