Vulnerability Description
HPE ArcSight ESM 5.x before 5.6, 6.0, 6.5.x before 6.5C SP1 Patch 2, and 6.8c before P1, and ArcSight ESM Express before 6.9.1, allows local users to gain privileges for command execution via unspecified vectors.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microfocus | Arcsight Enterprise Security Manager | <= 5.6 |
Related Weaknesses (CWE)
References
- http://www.securitytracker.com/id/1035282Third Party AdvisoryVDB Entry
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-cPatchVendor Advisory
- http://www.securitytracker.com/id/1035282Third Party AdvisoryVDB Entry
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-cPatchVendor Advisory
FAQ
What is CVE-2016-1990?
CVE-2016-1990 is a vulnerability with a CVSS score of 7.8 (HIGH). HPE ArcSight ESM 5.x before 5.6, 6.0, 6.5.x before 6.5C SP1 Patch 2, and 6.8c before P1, and ArcSight ESM Express before 6.9.1, allows local users to gain privileges for command execution via unspecif...
How severe is CVE-2016-1990?
CVE-2016-1990 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-1990?
Check the references section above for vendor advisories and patch information. Affected products include: Microfocus Arcsight Enterprise Security Manager.