CVE-2020-11844
CRITICAL
10.0
CVSS 3.1
Description
Incorrect Authorization vulnerability in Micro Focus Container Deployment Foundation component affects products: - Hybrid Cloud Management. Versions 2018.05 to 2019.11. - ArcSight Investigate. versions 2.4.0, 3.0.0 and 3.1.0. - ArcSight Transformation Hub. versions 3.0.0, 3.1.0, 3.2.0. - ArcSight Interset. version 6.0.0. - ArcSight ESM (when ArcSight Fusion 1.0 is installed). version 7.2.1. - Service Management Automation (SMA). versions 2018.05 to 2020.02 - Operation Bridge Suite (Containerized). Versions 2018.05 to 2020.02. - Network Operation Management. versions 2017.11 to 2019.11. - Data Center Automation Containerized. versions 2018.05 to 2019.11 - Identity Intelligence. versions 1.1.0 and 1.1.1. The vulnerability could be exploited to provide unauthorized access to the Container Deployment Foundation.
Metadata
Severity & Metrics
10.0
CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products (10)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Micro Focus | ArcSight ESM (when ArcSight Fusion | — | 7.2.1 |
| Micro Focus | ArcSight Interset | — | 6.0.0 |
| Micro Focus | ArcSight Investigate. versions | — | 2.4.0, 3.0.0, 3.1.0 |
| Micro Focus | ArcSight Transformation Hub | — | 3.0.0, 3.1.0, 3.2.0 |
| Micro Focus | Data Center Automation Containerized | — | 2018.05, 2018.08, 2018.11, 2019.02 … |
| Micro Focus | Hybrid Cloud Management | — | 2018.05 < 2019.11 |
| Micro Focus | Identity Intelligence. versions | — | 1.1.0, next of 1.1.1 < unspecified |
| Micro Focus | Network Operation Management | — | 2017.11 ≤ 2019.11 |
| Micro Focus | Operation Bridge Suite (Containerized) | — | 2018.05, 2018.08, 2018.11, 2019.02 … |
| Micro Focus | Service Management Automation (SMA) | — | 2018.05, 2018.08, 2018.11, 2019.02 … |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| CWE-863 | cna | CWE-863 Incorrect Authorization |
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 10.0 | CRITICAL | 3.1 | cna | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
References (7)
- https://softwaresupport.softwaregrp.com/doc/KM03645636
- https://softwaresupport.softwaregrp.com/doc/KM03645642
- https://softwaresupport.softwaregrp.com/doc/KM03645631
- https://softwaresupport.softwaregrp.com/doc/KM03645630
- https://softwaresupport.softwaregrp.com/doc/KM03645629
- https://softwaresupport.softwaregrp.com/doc/KM03645628
- https://support.microfocus.com/kb/doc.php?id=7024637