Category Archives: Checkpoint

Checkpoint

HPE Network Automation RMI Registry Insecure Deserialization (CVE-2016-4385)

An insecure deserialization vulnerability has been reported in the RMI registry of HPE Network Automation. The vulnerability is due to the deserialization of untrusted data. A remote attacker can exploit this vulnerability by sending a request with crafted serialized data to the exposed RMI registry. Successful exploitation would result in the execution of arbitrary code under the context of the RMI registry process.