CVE-2018-6491
MFSBGN03803 rev.1 - UCMDB, Installation File Access Control Privilege Escalation Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Local Escalation of Privilege vulnerability to Micro Focus Universal CMDB, versions 10.20, 10.21, 10.22, 10.30, 10.31, 10.32, 10.33, 11.00. The vulnerability could be remotely exploited to Local Escalation of Privilege.
Vulnerabilidad de escalado local de privilegios en Micro Focus Universal CMDB 10.20, 10.21, 10.22, 10.30, 10.31, 10.32, 10.33 y 11.00. La vulnerabilidad se podrĂa explotar de forma remota para permitir un escalado local de privilegios.
This vulnerability allows local attackers to escalate privilege on vulnerable installations of Hewlett Packard Enterprise Universal CMDB. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
The specific flaw exists within an access control set with insufficient privileges during the installation of the product. An attacker can leverage this vulnerability to execute arbitrary code under the context of SYSTEM.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-02-01 CVE Reserved
- 2018-04-12 CVE Published
- 2023-11-08 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.securitytracker.com/id/1040680 | Vdb Entry | |
https://softwaresupport.softwaregrp.com/document/-/facetsearch/document/KM03141180 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Microfocus Search vendor "Microfocus" | Ucmdb Configuration Manager Search vendor "Microfocus" for product "Ucmdb Configuration Manager" | 10.20 Search vendor "Microfocus" for product "Ucmdb Configuration Manager" and version "10.20" | - |
Affected
| ||||||
Microfocus Search vendor "Microfocus" | Ucmdb Configuration Manager Search vendor "Microfocus" for product "Ucmdb Configuration Manager" | 10.21 Search vendor "Microfocus" for product "Ucmdb Configuration Manager" and version "10.21" | - |
Affected
| ||||||
Microfocus Search vendor "Microfocus" | Ucmdb Configuration Manager Search vendor "Microfocus" for product "Ucmdb Configuration Manager" | 10.22 Search vendor "Microfocus" for product "Ucmdb Configuration Manager" and version "10.22" | - |
Affected
| ||||||
Microfocus Search vendor "Microfocus" | Ucmdb Configuration Manager Search vendor "Microfocus" for product "Ucmdb Configuration Manager" | 10.30 Search vendor "Microfocus" for product "Ucmdb Configuration Manager" and version "10.30" | - |
Affected
| ||||||
Microfocus Search vendor "Microfocus" | Ucmdb Configuration Manager Search vendor "Microfocus" for product "Ucmdb Configuration Manager" | 10.31 Search vendor "Microfocus" for product "Ucmdb Configuration Manager" and version "10.31" | - |
Affected
| ||||||
Microfocus Search vendor "Microfocus" | Ucmdb Configuration Manager Search vendor "Microfocus" for product "Ucmdb Configuration Manager" | 10.32 Search vendor "Microfocus" for product "Ucmdb Configuration Manager" and version "10.32" | - |
Affected
| ||||||
Microfocus Search vendor "Microfocus" | Ucmdb Configuration Manager Search vendor "Microfocus" for product "Ucmdb Configuration Manager" | 10.33 Search vendor "Microfocus" for product "Ucmdb Configuration Manager" and version "10.33" | - |
Affected
| ||||||
Microfocus Search vendor "Microfocus" | Ucmdb Configuration Manager Search vendor "Microfocus" for product "Ucmdb Configuration Manager" | 11.00 Search vendor "Microfocus" for product "Ucmdb Configuration Manager" and version "11.00" | - |
Affected
|