Medium severity6.1NVD Advisory· Published Oct 31, 2017· Updated May 13, 2026
CVE-2017-14357
CVE-2017-14357
Description
A Reflected and Stored Cross-Site Scripting (XSS) vulnerability in HP ArcSight ESM and HP ArcSight ESM Express, in any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1. This vulnerability could be exploited remotely to allow Reflected and Stored Cross-Site Scripting (XSS)
Affected products
4- Range: <6.9.1c Patch 4 or <6.11.0 Patch 1
- Range: <6.9.1c Patch 4 or <6.11.0 Patch 1
- Micro Focus/HP ArcSight ESMv5Range: Any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1
- Micro Focus/HP ArcSight ESM Expressv5Range: Any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.