HP
HP Arcsight Logger: vulnerabilidades y CVE
HP Arcsight Logger tiene 19 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE19
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2019-11656 | Media (5.4) | 0.64% | — | 4 oct 2019 | Stored XSS vulnerability in Micro Focus ArcSight Logger, affects versions prior to Logger 6.7.1 HotFix 6.7.1.8262.0. This vulnerability could allow Improper Neutralization of Input During Web Page Generation… |
| CVE-2019-11655 | Alta (8.8) | 1.5% | — | 4 oct 2019 | Unrestricted file upload vulnerability in Micro Focus ArcSight Logger, version 6.7.0 and later. This vulnerability could allow Unrestricted Upload of File with Dangerous type. |
| CVE-2019-3485 | Media (6.1) | 1.1% | — | 24 jul 2019 | Mitigates a stored cross site scripting issue in ArcSight Logger versions prior to 6.7.1 |
| CVE-2019-3484 | Alta (7.8) | 1.4% | — | 25 mar 2019 | Mitigates a remote code execution issue in ArcSight Logger versions prior to 6.7. |
| CVE-2019-3483 | Media (6.5) | 1.5% | — | 25 mar 2019 | Mitigates a potential information leakage issue in ArcSight Logger versions prior to 6.7. |
| CVE-2019-3482 | Media (6.5) | 4.2% | — | 25 mar 2019 | Mitigates a directory traversal issue in ArcSight Logger versions prior to 6.7. |
| CVE-2019-3481 | Alta (7.1) | 1.7% | — | 25 mar 2019 | Mitigates a XML External Entity Parsing issue in ArcSight Logger versions prior to 6.7. |
| CVE-2019-3480 | Media (6.1) | 1.3% | — | 25 mar 2019 | Mitigates a stored/reflected XSS issue in ArcSight Logger versions prior to 6.7. |
| CVE-2019-3479 | Crítica (9.8) | 6.9% | — | 25 mar 2019 | Mitigates a potential remote code execution issue in ArcSight Logger versions prior to 6.7. |
| CVE-2015-6864 | Media (6.3) | 0.85% | — | 16 ene 2016 | HPE ArcSight Logger before 6.1P1 allows remote authenticated users to execute arbitrary code via unspecified input to the (1) Intellicus or (2) client-certificate upload component. |
| CVE-2015-6863 | Alta (7.3) | 2.3% | — | 16 ene 2016 | HPE ArcSight Logger before 6.1P1 allows remote attackers to execute arbitrary code via unspecified input to the (1) Intellicus or (2) client-certificate upload component. |
| CVE-2015-5441 | Media (4.3) | 1.9% | — | 12 nov 2015 | Multiple cross-site scripting (XSS) vulnerabilities in HP ArcSight Management Center before 2.1 and ArcSight Logger before 6.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
| CVE-2015-6030 | Alta (7.2) | 0.61% | — | 4 nov 2015 | HP ArcSight Logger 6.0.0.7307.1, ArcSight Command Center 6.8.0.1896.0, and ArcSight Connector Appliance 6.4.0.6881.3 use the root account to execute files owned by the arcsight user, which might allow local users to… |
| CVE-2015-6029 | Media (5) | 4.4% | — | 4 nov 2015 | HP ArcSight Logger before 6.0 P2 does not limit attempts to authenticate to the SOAP interface, which makes it easier for remote attackers to obtain access via a brute-force approach. |
| CVE-2015-2136 | Media (4) | 1.8% | — | 16 sept 2015 | HP ArcSight Logger before 6.0 P2 allows remote authenticated users to bypass the intended authorization policy via unspecified vectors. |
| CVE-2014-7884 | Alta (9) | 12% | — | 14 mar 2015 | Multiple unspecified vulnerabilities in HP ArcSight Logger before 6.0P1 have unknown impact and remote authenticated attack vectors. |
| CVE-2012-5199 | Media (6.8) | 0.94% | — | 16 feb 2013 | Unspecified vulnerability in HP ArcSight Connector Appliance 6.3 and earlier and ArcSight Logger 5.2 and earlier allows remote authenticated users to execute arbitrary code via unknown vectors. |
| CVE-2012-5198 | Media (5) | 3.8% | — | 16 feb 2013 | Unspecified vulnerability in HP ArcSight Connector Appliance before 6.3 and ArcSight Logger 5.2 and earlier allows remote attackers to obtain sensitive information via unknown vectors. |
| CVE-2012-3286 | Media (6.5) | 2.4% | — | 16 feb 2013 | Unspecified vulnerability in HP ArcSight Connector Appliance 6.3 and earlier and ArcSight Logger 5.2 and earlier allows remote authenticated users to obtain sensitive information, modify data, or cause a denial of… |
Otros productos de HP
Intelligent Management Center · 310Hp-ux · 291Openview Network Node Manager · 80System Management Homepage · 78Instantos · 56XP7 Command View · 53Systems Insight Manager · 50Matrix Operating Environment · 34Tru64 · 32Network Node Manager I · 29Elitebook X360 1040 G6 Firmware · 28Elitebook X360 830 G6 Firmware · 28