Skip to main content

Vendor/product archive

hp / arcsight_logger CVEs

Beta · best-effort

19 CVEs tagged to hp / arcsight_logger2 Critical, 5 High, 12 Medium, 0 Low, 0 Unrated.

CVE-2019-11656

Published Oct 4, 2019

Stored XSS vulnerability in Micro Focus ArcSight Logger, affects versions prior to Logger 6.7.1 HotFix 6.7.1.8262.0. This vulnerability could allow Improper Neutralization of Inpu…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11655

Published Oct 4, 2019

Unrestricted file upload vulnerability in Micro Focus ArcSight Logger, version 6.7.0 and later. This vulnerability could allow Unrestricted Upload of File with Dangerous type.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-3485

Published Jul 24, 2019

Mitigates a stored cross site scripting issue in ArcSight Logger versions prior to 6.7.1

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-3484

Published Mar 25, 2019

Mitigates a remote code execution issue in ArcSight Logger versions prior to 6.7.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-3483

Published Mar 25, 2019

Mitigates a potential information leakage issue in ArcSight Logger versions prior to 6.7.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-3482

Published Mar 25, 2019

Mitigates a directory traversal issue in ArcSight Logger versions prior to 6.7.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-3481

Published Mar 25, 2019

Mitigates a XML External Entity Parsing issue in ArcSight Logger versions prior to 6.7.

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2019-3480

Published Mar 25, 2019

Mitigates a stored/reflected XSS issue in ArcSight Logger versions prior to 6.7.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-3479

Published Mar 25, 2019

Mitigates a potential remote code execution issue in ArcSight Logger versions prior to 6.7.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-6864

Published Jan 16, 2016

HPE ArcSight Logger before 6.1P1 allows remote authenticated users to execute arbitrary code via unspecified input to the (1) Intellicus or (2) client-certificate upload component.

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-6863

Published Jan 16, 2016

HPE ArcSight Logger before 6.1P1 allows remote attackers to execute arbitrary code via unspecified input to the (1) Intellicus or (2) client-certificate upload component.

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2015-6030

Published Nov 4, 2015

HP ArcSight Logger 6.0.0.7307.1, ArcSight Command Center 6.8.0.1896.0, and ArcSight Connector Appliance 6.4.0.6881.3 use the root account to execute files owned by the arcsight us…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2015-6029

Published Nov 4, 2015

HP ArcSight Logger before 6.0 P2 does not limit attempts to authenticate to the SOAP interface, which makes it easier for remote attackers to obtain access via a brute-force appro…

CVSS 5.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-2136

Published Sep 16, 2015

HP ArcSight Logger before 6.0 P2 allows remote authenticated users to bypass the intended authorization policy via unspecified vectors.

CVSS 4.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2014-7884

Published Mar 14, 2015

Multiple unspecified vulnerabilities in HP ArcSight Logger before 6.0P1 have unknown impact and remote authenticated attack vectors.

CVSS 9.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-19 of 19 CVEsPage 1 of 1