CVE-2018-6499
Published: Aug 30, 2018
Modified: Sep 17, 2024
CVSS v3.0
7.1
Description
Remote Code Execution in the following products Hybrid Cloud Management Containerized Suite HCM2017.11, HCM2018.02, HCM2018.05, Operations Bridge Containerized Suite 2017.11, 2018.02, 2018.05, Data Center Automation Containerized Suite 2017.01 until 2018.05, Service Management Automation Suite 2017.11, 2018.02, 2018.05, Service Virtualization (SV) with floating licenses using Any version using APLS older than 10.7, Unified Functional Testing (UFT) with floating licenses using Any version using APLS older than 10.7, Network Virtualization (NV) with floating licenses using Any version using APLS older than 10.7 and Network Operations Management (NOM) Suite CDF 2017.11, 2018.02, 2018.05 will allow Remote Code Execution.
| Vendor | Product | Versions |
|---|---|---|
Micro Focus | Network Operations Management (NOM) Suite CDF | affected 2017.11, 2018.02, 2018.05 |
Micro Focus | Service Management Automation Suite | affected 2017.11, 2018.02, 2018.05 |
Micro Focus | Data Center Automation Containerized Suite | affected 2017.01 until 2018.05 |
Micro Focus | Operations Bridge Containerized Suite | affected 2017.11, 2018.02, 2018.05 |
Micro Focus | Hybrid Cloud Management Containerized Suite | affected HCM2017.11, HCM2018.02, HCM2018.05 |
Micro Focus | Network Virtualization (NV) with floating licenses | affected using Any version using APLS older than 10.7 |
Micro Focus | Unified Functional Testing (UFT) with floating licenses | affected using Any version using APLS older than 10.7 |
Micro Focus | Service Virtualization (SV) with floating licenses | affected using Any version using APLS older than 10.7 |
CVSS v3.0 Details
CVSS v3.0 Vector
CVSS:3.0/AV:A/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now