CVE-2015-6030
Last modified
CVE-2015-6030 is a vulnerability of currently unknown severity. HP ArcSight Logger 6.0.0.7307.1, ArcSight Command Center 6.8.0.1896.0, and ArcSight Connector Appliance 6.4.0.6881.3 use the root account to execute files owned by the arcsight user, which might allow local users to gain privileges by leveraging arcsight account access.. EPSS estimates a 0.61% chance of exploitation in the next 30 days.
Description
HP ArcSight Logger 6.0.0.7307.1, ArcSight Command Center 6.8.0.1896.0, and ArcSight Connector Appliance 6.4.0.6881.3 use the root account to execute files owned by the arcsight user, which might allow local users to gain privileges by leveraging arcsight account access.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Hp | Arcsight Connector Appliance | <= 6.4.0.6881.3 | — |
| Hp | Arcsight Logger | 6.0.0.7307.1 | — |
| Hp | Arcsight Command Center | 6.8.0.1896.0 | — |
| Hp | Arcsight Connectors | <= 7.1.3 | — |
| Hp | Arcsight Express | 4.0 | — |
| Hp | Arcsight Management Center | <= 2.0 | P1 |
| Microfocus | Arcsight Enterprise Security Manager | <= 6.5 | — |
References
- http://www.kb.cert.org/vuls/id/842252Third Party Advisory, US Government Resource
- http://www.securitytracker.com/id/1034072Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1034073Third Party Advisory, VDB Entry
- http://www.kb.cert.org/vuls/id/842252Third Party Advisory, US Government Resource
- http://www.securitytracker.com/id/1034072Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1034073Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-6030?
How severe is CVE-2015-6030?
How do I fix CVE-2015-6030?
Are you affected by CVE-2015-6030?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
