CVE-2018-18589
Summary
| CVE | CVE-2018-18589 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-10-23 17:29:00 UTC |
| Updated | 2023-11-07 02:55:00 UTC |
| Description | A potential Remote Arbitrary Code Execution vulnerability has been identified in Micro Focus' Real User Monitoring software, versions 9.26IP, 9.30, 9.40 and 9.50. The vulnerability could be exploited to execute arbitrary code. |
Risk And Classification
Problem Types: CWE-502
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microfocus | Real User Monitoring | 9.26ip | All | All | All |
| Application | Microfocus | Real User Monitoring | 9.30 | All | All | All |
| Application | Microfocus | Real User Monitoring | 9.40 | All | All | All |
| Application | Microfocus | Real User Monitoring | 9.50 | All | All | All |
| Application | Microfocus | Real User Monitoring | 9.26ip | All | All | All |
| Application | Microfocus | Real User Monitoring | 9.30 | All | All | All |
| Application | Microfocus | Real User Monitoring | 9.40 | All | All | All |
| Application | Microfocus | Real User Monitoring | 9.50 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| MySupport - Micro Focus Software Support | CONFIRM | softwaresupport.softwaregrp.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Micro Focus would like to thank Deapesh Misra of iDefense Labs, Accenture for reporting this issue to [email protected].
There are currently no legacy QID mappings associated with this CVE.