CVE-2015-6030: HP Arcsight Command Center

High severity, CVSS 7.2. EPSS: 0.6% chance of exploitation in the next 30 days.

HP ArcSight Logger 6.0.0.7307.1, ArcSight Command Center 6.8.0.1896.0, and ArcSight Connector Appliance 6.4.0.6881.3 use the root account to execute files owned by the arcsight user, which might allow local users to gain privileges by leveraging arcsight account access.

Affected products

  • HP Arcsight Command Center: version 6.8.0.1896.0 only
  • HP Arcsight Connector Appliance: up to and including 6.4.0.6881.3
  • HP Arcsight Connectors: up to and including 7.1.3
  • HP Arcsight Express: version 4.0 only
  • HP Arcsight Logger: version 6.0.0.7307.1 only
  • HP Arcsight Management Center: up to and including 2.0
  • Micro Focus Arcsight Enterprise Security Manager: up to and including 6.5

Published 2015-11-04. Last modified 2026-06-17.