CVE-2021-38124

CRITICAL

Micro Focus ArcSight ESM <7.5 - RCE

Title source: llm
STIX 2.1

Description

Remote Code Execution vulnerability in Micro Focus ArcSight Enterprise Security Manager (ESM) product, affecting versions 7.0.2 through 7.5. The vulnerability could be exploited resulting in remote code execution.

References (1)

Core 1
Core References
Various Sources x_refsource_misc
https://portal.microfocus.com/s/article/KM000001960

Scores

CVSS v3 9.8
EPSS 0.0209
EPSS Percentile 84.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-77
Status published
Products (1)
microfocus/arcsight_enterprise_security_manager 7.0.2 - 7.5
Published Sep 28, 2021
Tracked Since Feb 18, 2026