CVE-2016-4377
Last modified
CVE-2016-4377 is a vulnerability of currently unknown severity. HPE Smart Update in Storage Sizing Tool before 13.0, Converged Infrastructure Solution Sizer Suite (CISSS) before 2.13.1, Power Advisor before 7.8.2, Insight Management Sizer before 16.12.1, Synergy Planning Tool before 3.3, SAP Sizing Tool before 16.12.1, Sizing Tool for SAP Business Suite powered by HANA before 16.11.1, Sizer for ConvergedSystems Virtualization before 16.7.1, Sizer for Microsoft Exchange Server before 16.12.1, Sizer for Microsoft Lync Server 2013 before 16.12.1, Sizer for Microsoft SharePoint 2013 before 16.13.1, Sizer for Microsoft SharePoint 2010 before 16.11.1, and Sizer for Microsoft Skype for Business Server 2015 before 16.5.1 allows remote attackers to execute arbitrary code via unspecified vectors.. EPSS estimates a 7.20% chance of exploitation in the next 30 days.
Description
HPE Smart Update in Storage Sizing Tool before 13.0, Converged Infrastructure Solution Sizer Suite (CISSS) before 2.13.1, Power Advisor before 7.8.2, Insight Management Sizer before 16.12.1, Synergy Planning Tool before 3.3, SAP Sizing Tool before 16.12.1, Sizing Tool for SAP Business Suite powered by HANA before 16.11.1, Sizer for ConvergedSystems Virtualization before 16.7.1, Sizer for Microsoft Exchange Server before 16.12.1, Sizer for Microsoft Lync Server 2013 before 16.12.1, Sizer for Microsoft SharePoint 2013 before 16.13.1, Sizer for Microsoft SharePoint 2010 before 16.11.1, and Sizer for Microsoft Skype for Business Server 2015 before 16.5.1 allows remote attackers to execute arbitrary code via unspecified vectors.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hp | Converged Infrastructure Solution Sizer Suite | <= 2.13.0 |
| Hp | Insight Management Sizer | <= 16.12.0 |
| Hp | Power Advisor | <= 7.8.1 |
| Hp | Sap Sizing Tool | <= 16.12.0 |
| Hp | Sizer For Converged Systems Virtualization | <= 16.7.0 |
| Hp | Sizer For Microsoft Exchange Server 2010 | <= 16.12.0 |
| Hp | Sizer For Microsoft Exchange Server 2013 | <= 16.12.0 |
| Hp | Sizer For Microsoft Exchange Server 2016 | <= 16.12.0 |
| Hp | Sizer For Microsoft Lync Server 2013 | <= 16.12.0 |
| Hp | Sizer For Microsoft Sharepoint 2010 | <= 16.11.0 |
| Hp | Sizer For Microsoft Sharepoint 2013 | <= 16.13.0 |
| Hp | Sizer For Microsoft Skype For Business Server 2015 | <= 16.5.0 |
| Hp | Sizing Tool For Sap Business Suite Powered By Hana | <= 16.11.0 |
| Hp | Storage Sizing Tool | <= 13.0 |
| Hp | Synergy Planning Tool | <= 3.2 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-4377?
How severe is CVE-2016-4377?
How do I fix CVE-2016-4377?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-4371HPE Service Manager Software 9.30, 9.31, 9.32, 9.33, 9.34, 9…
- CVE-2016-4372HPE iMC PLAT before 7.2 E0403P04, iMC EAD before 7.2 E0405P0…
- CVE-2016-4373The AdminUI in HPE Operations Manager (OM) before 9.21.130 o…
- CVE-2016-4374HPE Release Control (RC) 9.13, 9.20, and 9.21 before 9.21.00…
- CVE-2016-4375Multiple unspecified vulnerabilities in HPE Integrated Light…
- CVE-2016-4376HPE FOS before 7.4.1d and 8.x before 8.0.1 on StoreFabric B …
- CVE-2016-4378The (1) Device Manager, (2) Tiered Storage Manager, (3) Repl…
- CVE-2016-4379The TLS implementation in HPE Integrated Lights-Out 3 (aka i…
- CVE-2016-4380Cross-site scripting (XSS) vulnerability in the AdminUI in H…
- CVE-2016-4381HPE XP7 Command View Advanced Edition (CVAE) Suite 6.x throu…
- CVE-2016-4382HPE Performance Center 11.52, 12.00, 12.01, 12.20, and 12.50…
- CVE-2016-4383The glance-manage db in all versions of HPE Helion Openstack…
Are you affected by CVE-2016-4377?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
