CVE Database
/

CVE-2020-11844

Back to search

CVE-2020-11844

Published: May 29, 2020

Modified: Aug 4, 2024

PUBLISHED

CVSS v3.1

10.0

CRITICAL

Description

Incorrect Authorization vulnerability in Micro Focus Container Deployment Foundation component affects products: - Hybrid Cloud Management. Versions 2018.05 to 2019.11. - ArcSight Investigate. versions 2.4.0, 3.0.0 and 3.1.0. - ArcSight Transformation Hub. versions 3.0.0, 3.1.0, 3.2.0. - ArcSight Interset. version 6.0.0. - ArcSight ESM (when ArcSight Fusion 1.0 is installed). version 7.2.1. - Service Management Automation (SMA). versions 2018.05 to 2020.02 - Operation Bridge Suite (Containerized). Versions 2018.05 to 2020.02. - Network Operation Management. versions 2017.11 to 2019.11. - Data Center Automation Containerized. versions 2018.05 to 2019.11 - Identity Intelligence. versions 1.1.0 and 1.1.1. The vulnerability could be exploited to provide unauthorized access to the Container Deployment Foundation.

VendorProductVersions

Micro Focus

Hybrid Cloud Management

affected
2018.05 - < 2019.11

Micro Focus

ArcSight Investigate. versions

affected
2.4.0
affected
3.0.0
affected
3.1.0

Micro Focus

ArcSight Transformation Hub

affected
3.0.0
affected
3.1.0
affected
3.2.0

Micro Focus

ArcSight Interset

affected
6.0.0

Micro Focus

ArcSight ESM (when ArcSight Fusion

affected
7.2.1

Micro Focus

Service Management Automation (SMA)

affected
2018.05
affected
2018.08
affected
2018.11
affected
2019.02
affected
2019.05

+3 more versions

Micro Focus

Operation Bridge Suite (Containerized)

affected
2018.05
affected
2018.08
affected
2018.11
affected
2019.02
affected
2019.05

+2 more versions

Micro Focus

Network Operation Management

affected
2017.11 - <= 2019.11

Micro Focus

Data Center Automation Containerized

affected
2018.05
affected
2018.08
affected
2018.11
affected
2019.02
affected
2019.05

+2 more versions

Micro Focus

Identity Intelligence. versions

affected
1.1.0
unaffected
next of 1.1.1 - < unspecified

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Changed

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now