CVE-2016-1990: High severity opentext arcsight enterprise security manager vulnerability
HPE ArcSight ESM 5.x before 5.6, 6.0, 6.5.x before 6.5C SP1 Patch 2, and 6.8c before P1, and ArcSight ESM Express before 6.9.1, allows local users to gain privileges for command execution via unspecified vectors.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1990?
CVE-2016-1990 is classified as a high severity vulnerability due to its potential to allow local users to gain elevated privileges.
How do I fix CVE-2016-1990?
To fix CVE-2016-1990, upgrade the affected ArcSight ESM versions to 5.6 or later, or to 6.5C SP1 Patch 2 or later.
Who is affected by CVE-2016-1990?
Local users of HPE ArcSight ESM versions prior to 5.6, 6.0, 6.5C SP1 Patch 2, and ESM Express versions before 6.9.1 are affected by CVE-2016-1990.
What type of vulnerability is CVE-2016-1990?
CVE-2016-1990 is a privilege escalation vulnerability that allows local command execution.
Is CVE-2016-1990 exploitable remotely?
No, CVE-2016-1990 is only exploitable by local users with access to the affected systems.