CVE-2015-6030
Summary
| CVE | CVE-2015-6030 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-11-04 03:59:00 UTC |
| Updated | 2018-10-17 18:44:00 UTC |
| Description | HP ArcSight Logger 6.0.0.7307.1, ArcSight Command Center 6.8.0.1896.0, and ArcSight Connector Appliance 6.4.0.6881.3 use the root account to execute files owned by the arcsight user, which might allow local users to gain privileges by leveraging arcsight account access. |
Risk And Classification
Problem Types: CWE-264
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Hp | Arcsight Command Center | 6.8.0.1896.0 | All | All | All |
| Application | Hp | Arcsight Command Center | 6.8.0.1896.0 | All | All | All |
| Application | Hp | Arcsight Connectors | All | All | All | All |
| Application | Hp | Arcsight Connector Appliance | All | All | All | All |
| Application | Hp | Arcsight Express | 4.0 | All | All | All |
| Application | Hp | Arcsight Express | 4.0 | p1 | All | All |
| Application | Hp | Arcsight Express | 4.0 | All | All | All |
| Application | Hp | Arcsight Express | 4.0 | p1 | All | All |
| Application | Hp | Arcsight Logger | 6.0.0.7307.1 | All | All | All |
| Application | Hp | Arcsight Logger | 6.0.0.7307.1 | All | All | All |
| Application | Hp | Arcsight Management Center | All | p1 | All | All |
| Application | Microfocus | Arcsight Enterprise Security Manager | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Document Display | HPE Support Center | CONFIRM | h20566.www2.hpe.com | Third Party Advisory |
| HP ArcSight SmartConnectors Unsafe File Permissions Let Local Users Gain Elevated Privileges - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| HP ArcSight Enterprise Security Manager Unsafe File Permissions Let Local Users Gain Elevated Privileges - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| Vulnerability Note VU#842252 - HP ArcSight Logger contains multiple vulnerabilities | CERT-VN | www.kb.cert.org | Third Party Advisory, US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.