CVE-2015-6030
Summary
| CVE | CVE-2015-6030 |
|---|---|
| State | PUBLISHED |
| Assigner | certcc |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-11-04 03:59:08 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | HP ArcSight Logger 6.0.0.7307.1, ArcSight Command Center 6.8.0.1896.0, and ArcSight Connector Appliance 6.4.0.6881.3 use the root account to execute files owned by the arcsight user, which might allow local users to gain privileges by leveraging arcsight account access. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:L/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Hp | Arcsight Command Center | 6.8.0.1896.0 | All | All | All |
| Application | Hp | Arcsight Connectors | All | All | All | All |
| Application | Hp | Arcsight Connector Appliance | All | All | All | All |
| Application | Hp | Arcsight Express | 4.0 | All | All | All |
| Application | Hp | Arcsight Express | 4.0 | p1 | All | All |
| Application | Hp | Arcsight Logger | 6.0.0.7307.1 | All | All | All |
| Application | Hp | Arcsight Management Center | All | p1 | All | All |
| Application | Microfocus | Arcsight Enterprise Security Manager | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| HP ArcSight Enterprise Security Manager Unsafe File Permissions Let Local Users Gain Elevated Privileges - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Third Party Advisory, VDB Entry |
| Vulnerability Note VU#842252 - HP ArcSight Logger contains multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | Third Party Advisory, US Government Resource |
| HP ArcSight SmartConnectors Unsafe File Permissions Let Local Users Gain Elevated Privileges - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Third Party Advisory, VDB Entry |
| Document Display | HPE Support Center | af854a3a-2127-422b-91ae-364da2661108 | h20566.www2.hpe.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.