Poly Clariti Manager Deserialization Vulnerability Allowing Remote Code Execution

Vulnerability

A deserialization vulnerability has been identified in Poly Clariti Manager versions prior to 10.12.1. This vulnerability allows for the deserialization of untrusted data without proper validation, potentially leading to remote code execution. HP has released a patch for this issue in version 10.12.2.

Impact

Exploitation of this vulnerability could lead to remote code execution on the affected system.

Remediation

Users are advised to update to version 10.12.2 or later. The latest builds can be obtained through the Poly Lens Management Console.

Added: Jul 23, 2025, 12:17 AM
Updated: Jul 23, 2025, 12:17 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
4.8
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.