CVE-2020-8574Active IQ Unified Manager vulnerability

3 documents3 sources
Severity
7.8HIGHNVD
EPSS
0.2%
top 63.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 3
Latest updateMay 24

Description

Active IQ Unified Manager for Linux versions prior to 9.6 ship with the Java Management Extension Remote Method Invocation (JMX RMI) service enabled allowing unauthorized code execution to local users.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-gjfj-j9px-jqww: Active IQ Unified Manager for Linux versions prior to 92022-05-24
CVEList
CVE-2020-8574: Active IQ Unified Manager for Linux versions prior to 92020-08-03
CVE-2020-8574 — Active IQ Unified Manager vulnerability | cvebase