CVE-2021-38124

Remote Code Execution vulnerability in Micro Focus ArcSight Enterprise Security Manager (ESM) product, affecting versions 7.0.2 through 7.5. The vulnerability could be exploited resulting in remote code execution.
Configurations

Configuration 1 (hide)

cpe:2.3:a:microfocus:arcsight_enterprise_security_manager:*:*:*:*:*:*:*:*

History

07 Nov 2023, 03:37

Type Values Removed Values Added
References (MISC) https://portal.microfocus.com/s/article/KM000001960 - Patch, Vendor Advisory () https://portal.microfocus.com/s/article/KM000001960 -

01 Oct 2021, 20:41

Type Values Removed Values Added
CPE cpe:2.3:a:microfocus:arcsight_enterprise_security_manager:*:*:*:*:*:*:*:*
CWE CWE-77
References (MISC) https://portal.microfocus.com/s/article/KM000001960 - (MISC) https://portal.microfocus.com/s/article/KM000001960 - Patch, Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 7.5
v3 : 9.8

28 Sep 2021, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-09-28 14:15

Updated : 2023-12-10 14:09


NVD link : CVE-2021-38124

Mitre link : CVE-2021-38124

CVE.ORG link : CVE-2021-38124


JSON object : View

Products Affected

microfocus

  • arcsight_enterprise_security_manager
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')