CVE-2017-6885: Critical severity flexera flexnet manager suite vulnerability
Published May 16, 2017
·Updated
An error when handling certain external commands and services related to the FlexNet Inventory Agent and FlexNet Beacon of the Flexera Software FlexNet Manager Suite 2017 before 2017 R1 and 2014 R3 through 2016 R1 SP1 can be exploited to gain elevated privileges.
Affected Software
4 affected components
Flexerasoftware Flexnet Manager Suite=2014
Flexerasoftware Flexnet Manager Suite=2015
Flexerasoftware Flexnet Manager Suite=2016
Flexerasoftware Flexnet Manager Suite=2017
Event History
May 16, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-6885?
CVE-2017-6885 is considered to have a moderate severity due to its potential to elevate privileges.
2
How do I fix CVE-2017-6885?
To fix CVE-2017-6885, upgrade FlexNet Manager Suite to version 2017 R1 or a later version.
3
What software is affected by CVE-2017-6885?
CVE-2017-6885 impacts FlexNet Manager Suite versions 2014 through 2017 prior to R1.
4
What type of vulnerability is CVE-2017-6885?
CVE-2017-6885 is a privilege escalation vulnerability related to external command handling.
5
Is there a workaround for CVE-2017-6885?
There is no known workaround for CVE-2017-6885; updating to a secure version is recommended.