---
cve: "CVE-2018-6487"
severity: "CRITICAL"
cvss: 9.8
epss: "1.9%"
vendor: "Micro Focus"
kev: false
exploited: false
published: "2018-02-20 21:29:00"
tags: [cve, security, critical]
source: tsecurity.de CVE-Dossier
exported: "2026-09-10T08:46:43+02:00"
---

# CVE-2018-6487

> 9.8 CRITICAL

## Beschreibung

Remote Disclosure of Information in Micro Focus Universal CMDB Foundation Software, version numbers 10.10, 10.11, 10.20, 10.21, 10.22, 10.30, 10.31, 4.10, 4.11. This vulnerability could be remotely exploited to allow disclosure of information.

## CVSS-Vektor

```
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Referenzen

- <https://softwaresupport.softwaregrp.com/document/-/facetsearch/document/KM03091097>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2018-6487) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
