CVE Vulnerabilities

CVE-2019-3475

Improper Privilege Management

Published: Feb 20, 2019 | Modified: Nov 07, 2023
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

A local privilege escalation vulnerability in the famtd component of Micro Focus Filr 3.0 allows a local attacker authenticated as a low privilege user to escalate to root. This vulnerability affects all versions of Filr 3.x prior to Security Update 6.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Filr Microfocus 3.0 (including) 3.0 (including)
Filr Microfocus 3.0-update_1 (including) 3.0-update_1 (including)
Filr Microfocus 3.0-update_2 (including) 3.0-update_2 (including)
Filr Microfocus 3.0-update_3 (including) 3.0-update_3 (including)
Filr Microfocus 3.0-update_4 (including) 3.0-update_4 (including)
Filr Microfocus 3.0-update_5 (including) 3.0-update_5 (including)

Potential Mitigations

References