CVE-2016-1990: Micro Focus Arcsight Enterprise Security Manager

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

HPE ArcSight ESM 5.x before 5.6, 6.0, 6.5.x before 6.5C SP1 Patch 2, and 6.8c before P1, and ArcSight ESM Express before 6.9.1, allows local users to gain privileges for command execution via unspecified vectors.

Affected products

  • Micro Focus Arcsight Enterprise Security Manager: up to and including 5.6; version 6.0 only; version 6.5 only; version 6.8 only; version 6.9 only

Published 2016-03-16. Last modified 2026-06-17.