Описание
HP ArcSight Logger 6.0.0.7307.1, ArcSight Command Center 6.8.0.1896.0, and ArcSight Connector Appliance 6.4.0.6881.3 use the root account to execute files owned by the arcsight user, which might allow local users to gain privileges by leveraging arcsight account access.
Ссылки
- Third Party AdvisoryUS Government Resource
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Third Party Advisory
- Third Party AdvisoryUS Government Resource
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 6.4.0.6881.3 (включая)
cpe:2.3:a:hp:arcsight_connector_appliance:*:*:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:a:hp:arcsight_logger:6.0.0.7307.1:*:*:*:*:*:*:*
Конфигурация 3
cpe:2.3:a:hp:arcsight_command_center:6.8.0.1896.0:*:*:*:*:*:*:*
Конфигурация 4Версия до 7.1.3 (включая)Версия до 2.0 (включая)Версия до 6.5 (включая)
Одно из
cpe:2.3:a:hp:arcsight_connectors:*:*:*:*:*:*:*:*
cpe:2.3:a:hp:arcsight_express:4.0:*:*:*:*:*:*:*
cpe:2.3:a:hp:arcsight_express:4.0:p1:*:*:*:*:*:*
cpe:2.3:a:hp:arcsight_management_center:*:p1:*:*:*:*:*:*
cpe:2.3:a:microfocus:arcsight_enterprise_security_manager:*:*:*:*:*:*:*:*
EPSS
Процентиль: 76%
0.00975
Низкий
7.2 High
CVSS2
Дефекты
CWE-264
Связанные уязвимости
github
больше 3 лет назад
HP ArcSight Logger 6.0.0.7307.1, ArcSight Command Center 6.8.0.1896.0, and ArcSight Connector Appliance 6.4.0.6881.3 use the root account to execute files owned by the arcsight user, which might allow local users to gain privileges by leveraging arcsight account access.
EPSS
Процентиль: 76%
0.00975
Низкий
7.2 High
CVSS2
Дефекты
CWE-264