CVE-2016-4377 - CVE House
Back to Database
Status published High CVE-2016-4377

HPE Smart Update in Storage Sizing Tool before 13.0, Converged...

Vulnerability Description

HPE Smart Update in Storage Sizing Tool before 13.0, Converged Infrastructure Solution Sizer Suite (CISSS) before 2.13.1, Power Advisor before 7.8.2, Insight Management Sizer before 16.12.1, Synergy Planning Tool before 3.3, SAP Sizing Tool before 16.12.1, Sizing Tool for SAP Business Suite powered by HANA before 16.11.1, Sizer for ConvergedSystems Virtualization before 16.7.1, Sizer for Microsoft Exchange Server before 16.12.1, Sizer for Microsoft Lync Server 2013 before 16.12.1, Sizer for Microsoft SharePoint 2013 before 16.13.1, Sizer for Microsoft SharePoint 2010 before 16.11.1, and Sizer for Microsoft Skype for Business Server 2015 before 16.5.1 allows remote attackers to execute arbitrary code via unspecified vectors.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2016-4377

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

converged infrastructure solution sizer suite, insight management sizer, power advisor, sap sizing tool, sizer for converged systems virtualization, sizer for microsoft exchange server 2010, sizer for microsoft exchange server 2013, sizer for microsoft exchange server 2016, sizer for microsoft lync server 2013, sizer for microsoft sharepoint 2010, sizer for microsoft sharepoint 2013, sizer for microsoft skype for business server 2015, sizing tool for sap business suite powered by hana, storage sizing tool, synergy planning tool
Vulnerable Versions:
0

Timeline

Official Publish: August 22nd, 2016
Last Modified: August 6th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.