Attacker Value
Unknown
(0 users assessed)
Exploitability
Unknown
(0 users assessed)
User Interaction
None
Privileges Required
None
Attack Vector
Network
0

CVE-2020-11844

Disclosure Date: May 29, 2020
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

Incorrect Authorization vulnerability in Micro Focus Container Deployment Foundation component affects products: – Hybrid Cloud Management. Versions 2018.05 to 2019.11. – ArcSight Investigate. versions 2.4.0, 3.0.0 and 3.1.0. – ArcSight Transformation Hub. versions 3.0.0, 3.1.0, 3.2.0. – ArcSight Interset. version 6.0.0. – ArcSight ESM (when ArcSight Fusion 1.0 is installed). version 7.2.1. – Service Management Automation (SMA). versions 2018.05 to 2020.02 – Operation Bridge Suite (Containerized). Versions 2018.05 to 2020.02. – Network Operation Management. versions 2017.11 to 2019.11. – Data Center Automation Containerized. versions 2018.05 to 2019.11 – Identity Intelligence. versions 1.1.0 and 1.1.1. The vulnerability could be exploited to provide unauthorized access to the Container Deployment Foundation.

Add Assessment

No one has assessed this topic. Be the first to add your voice to the community.

CVSS V3 Severity and Metrics
Base Score:
9.8 Critical
Impact Score:
5.9
Exploitability Score:
3.9
Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector (AV):
Network
Attack Complexity (AC):
Low
Privileges Required (PR):
None
User Interaction (UI):
None
Scope (S):
Unchanged
Confidentiality (C):
High
Integrity (I):
High
Availability (A):
High

General Information

Technical Analysis