CVE-2015-6030
Last modified
CVE-2015-6030 is a vulnerability of currently unknown severity. HP ArcSight Logger 6.0.0.7307.1, ArcSight Command Center 6.8.0.1896.0, and ArcSight Connector Appliance 6.4.0.6881.3 use the root account to execute files owned by the arcsight user, which might allow local users to gain privileges by leveraging arcsight account access.. EPSS estimates a 0.61% chance of exploitation in the next 30 days.
Description
HP ArcSight Logger 6.0.0.7307.1, ArcSight Command Center 6.8.0.1896.0, and ArcSight Connector Appliance 6.4.0.6881.3 use the root account to execute files owned by the arcsight user, which might allow local users to gain privileges by leveraging arcsight account access.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Hp | Arcsight Connector Appliance | <= 6.4.0.6881.3 | — |
| Hp | Arcsight Logger | 6.0.0.7307.1 | — |
| Hp | Arcsight Command Center | 6.8.0.1896.0 | — |
| Hp | Arcsight Connectors | <= 7.1.3 | — |
| Hp | Arcsight Express | 4.0 | — |
| Hp | Arcsight Management Center | <= 2.0 | P1 |
| Microfocus | Arcsight Enterprise Security Manager | <= 6.5 | — |
References
- http://www.kb.cert.org/vuls/id/842252Third Party Advisory, US Government Resource
- http://www.securitytracker.com/id/1034072Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1034073Third Party Advisory, VDB Entry
- http://www.kb.cert.org/vuls/id/842252Third Party Advisory, US Government Resource
- http://www.securitytracker.com/id/1034072Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1034073Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-6030?
How severe is CVE-2015-6030?
How do I fix CVE-2015-6030?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-6022Unrestricted file upload vulnerability in QNAP Signage Stati…
- CVE-2015-6023ping.cgi in NetCommWireless HSPA 3G10WVE wireless routers wi…
- CVE-2015-6024ping.cgi in NetCommWireless HSPA 3G10WVE wireless routers wi…
- CVE-2015-6027Castle Rock Computing SNMPc before 2015-12-17 has XSS via SN…6.1
- CVE-2015-6028Castle Rock Computing SNMPc before 2015-12-17 has SQL inject…8.8
- CVE-2015-6029HP ArcSight Logger before 6.0 P2 does not limit attempts to …
- CVE-2015-6031Buffer overflow in the IGDstartelt function in igd_desc_pars…
- CVE-2015-6032Qolsys IQ Panel (aka QOL) before 1.5.1 has hardcoded cryptog…
- CVE-2015-6033Qolsys IQ Panel (aka QOL) before 1.5.1 does not verify the d…
- CVE-2015-6034EPSON Network Utility 4.10 uses weak permissions (Everyone: …
- CVE-2015-6035Opsview before 2015-11-06 has XSS via SNMP.
- CVE-2015-6036QNAP Signage Station before 2.0.1 allows remote attackers to…
Are you affected by CVE-2015-6030?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
