« Volver al listado

HP

HP Arcsight Logger: vulnerabilidades y CVE

HP Arcsight Logger tiene 19 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE19
Últimos 12 meses0
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2019-11656Media (5.4)0.64%—4 oct 2019
Stored XSS vulnerability in Micro Focus ArcSight Logger, affects versions prior to Logger 6.7.1 HotFix 6.7.1.8262.0. This vulnerability could allow Improper Neutralization of Input During Web Page Generation…
CVE-2019-11655Alta (8.8)1.5%—4 oct 2019
Unrestricted file upload vulnerability in Micro Focus ArcSight Logger, version 6.7.0 and later. This vulnerability could allow Unrestricted Upload of File with Dangerous type.
CVE-2019-3485Media (6.1)1.1%—24 jul 2019
Mitigates a stored cross site scripting issue in ArcSight Logger versions prior to 6.7.1
CVE-2019-3484Alta (7.8)1.4%—25 mar 2019
Mitigates a remote code execution issue in ArcSight Logger versions prior to 6.7.
CVE-2019-3483Media (6.5)1.5%—25 mar 2019
Mitigates a potential information leakage issue in ArcSight Logger versions prior to 6.7.
CVE-2019-3482Media (6.5)4.2%—25 mar 2019
Mitigates a directory traversal issue in ArcSight Logger versions prior to 6.7.
CVE-2019-3481Alta (7.1)1.7%—25 mar 2019
Mitigates a XML External Entity Parsing issue in ArcSight Logger versions prior to 6.7.
CVE-2019-3480Media (6.1)1.3%—25 mar 2019
Mitigates a stored/reflected XSS issue in ArcSight Logger versions prior to 6.7.
CVE-2019-3479Crítica (9.8)6.9%—25 mar 2019
Mitigates a potential remote code execution issue in ArcSight Logger versions prior to 6.7.
CVE-2015-6864Media (6.3)0.85%—16 ene 2016
HPE ArcSight Logger before 6.1P1 allows remote authenticated users to execute arbitrary code via unspecified input to the (1) Intellicus or (2) client-certificate upload component.
CVE-2015-6863Alta (7.3)2.3%—16 ene 2016
HPE ArcSight Logger before 6.1P1 allows remote attackers to execute arbitrary code via unspecified input to the (1) Intellicus or (2) client-certificate upload component.
CVE-2015-5441Media (4.3)1.9%—12 nov 2015
Multiple cross-site scripting (XSS) vulnerabilities in HP ArcSight Management Center before 2.1 and ArcSight Logger before 6.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2015-6030Alta (7.2)0.61%—4 nov 2015
HP ArcSight Logger 6.0.0.7307.1, ArcSight Command Center 6.8.0.1896.0, and ArcSight Connector Appliance 6.4.0.6881.3 use the root account to execute files owned by the arcsight user, which might allow local users to…
CVE-2015-6029Media (5)4.4%—4 nov 2015
HP ArcSight Logger before 6.0 P2 does not limit attempts to authenticate to the SOAP interface, which makes it easier for remote attackers to obtain access via a brute-force approach.
CVE-2015-2136Media (4)1.8%—16 sept 2015
HP ArcSight Logger before 6.0 P2 allows remote authenticated users to bypass the intended authorization policy via unspecified vectors.
CVE-2014-7884Alta (9)12%—14 mar 2015
Multiple unspecified vulnerabilities in HP ArcSight Logger before 6.0P1 have unknown impact and remote authenticated attack vectors.
CVE-2012-5199Media (6.8)0.94%—16 feb 2013
Unspecified vulnerability in HP ArcSight Connector Appliance 6.3 and earlier and ArcSight Logger 5.2 and earlier allows remote authenticated users to execute arbitrary code via unknown vectors.
CVE-2012-5198Media (5)3.8%—16 feb 2013
Unspecified vulnerability in HP ArcSight Connector Appliance before 6.3 and ArcSight Logger 5.2 and earlier allows remote attackers to obtain sensitive information via unknown vectors.
CVE-2012-3286Media (6.5)2.4%—16 feb 2013
Unspecified vulnerability in HP ArcSight Connector Appliance 6.3 and earlier and ArcSight Logger 5.2 and earlier allows remote authenticated users to obtain sensitive information, modify data, or cause a denial of…

Otros productos de HP