CVE-2015-6030

UnknownEPSS 0.61%

Last modified

CVE-2015-6030 is a vulnerability of currently unknown severity. HP ArcSight Logger 6.0.0.7307.1, ArcSight Command Center 6.8.0.1896.0, and ArcSight Connector Appliance 6.4.0.6881.3 use the root account to execute files owned by the arcsight user, which might allow local users to gain privileges by leveraging arcsight account access.. EPSS estimates a 0.61% chance of exploitation in the next 30 days.

Description

HP ArcSight Logger 6.0.0.7307.1, ArcSight Command Center 6.8.0.1896.0, and ArcSight Connector Appliance 6.4.0.6881.3 use the root account to execute files owned by the arcsight user, which might allow local users to gain privileges by leveraging arcsight account access.

Metrics

EPSS Probability
0.61%

44.5th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
HpArcsight Connector Appliance<= 6.4.0.6881.3
HpArcsight Logger6.0.0.7307.1
HpArcsight Command Center6.8.0.1896.0
HpArcsight Connectors<= 7.1.3
HpArcsight Express4.0
HpArcsight Management Center<= 2.0P1
MicrofocusArcsight Enterprise Security Manager<= 6.5

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2015-6030?
HP ArcSight Logger 6.0.0.7307.1, ArcSight Command Center 6.8.0.1896.0, and ArcSight Connector Appliance 6.4.0.6881.3 use the root account to execute files owned by the arcsight user, which might allow local users to gain privileges by leveraging arcsight account access.
How severe is CVE-2015-6030?
Severity scoring for CVE-2015-6030 is pending analysis. The EPSS model estimates a 0.61% probability of exploitation in the next 30 days.
How do I fix CVE-2015-6030?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2015-6030?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST