ArcSight Logger
by Microfocus
CVEs (30)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-11851 | Cri | 0.64 | 9.8 | 0.03 | Nov 17, 2020 | Arbitrary code execution vulnerability on Micro Focus ArcSight Logger product, affecting all version prior to 7.1.1. The vulnerability could be remotely exploited resulting in the execution of arbitrary code. | ||
| CVE-2019-3479 | Cri | 0.64 | 9.8 | 0.07 | Mar 25, 2019 | Mitigates a potential remote code execution issue in ArcSight Logger versions prior to 6.7. | ||
| CVE-2023-24470 | Cri | 0.59 | 9.1 | 0.01 | Jun 13, 2023 | Potential XML External Entity Injection in ArcSight Logger versions prior to 7.3.0. | ||
| CVE-2019-11657 | Hig | 0.57 | 8.8 | 0.00 | Dec 17, 2019 | Cross-Site Request Forgery vulnerability in all Micro Focus ArcSight Logger affecting all product versions below version 7.0. The vulnerability could be exploited to perform CSRF attack. | ||
| CVE-2019-11655 | Hig | 0.57 | 8.8 | 0.02 | Oct 4, 2019 | Unrestricted file upload vulnerability in Micro Focus ArcSight Logger, version 6.7.0 and later. This vulnerability could allow Unrestricted Upload of File with Dangerous type. | ||
| CVE-2024-4190 | Hig | 0.53 | 8.1 | 0.00 | Jun 11, 2024 | Stored Cross-Site Scripting (XSS) vulnerabilities have been identified in OpenText ArcSight Logger. The vulnerabilities could be remotely exploited. | ||
| CVE-2019-3484 | Hig | 0.51 | 7.8 | 0.01 | Mar 25, 2019 | Mitigates a remote code execution issue in ArcSight Logger versions prior to 6.7. | ||
| CVE-2015-6863 | Hig | 0.48 | 7.3 | 0.02 | Jan 16, 2016 | HPE ArcSight Logger before 6.1P1 allows remote attackers to execute arbitrary code via unspecified input to the (1) Intellicus or (2) client-certificate upload component. | ||
| CVE-2019-3481 | Hig | 0.46 | 7.1 | 0.02 | Mar 25, 2019 | Mitigates a XML External Entity Parsing issue in ArcSight Logger versions prior to 6.7. | ||
| CVE-2019-3482 | Med | 0.43 | 6.5 | 0.04 | Mar 25, 2019 | Mitigates a directory traversal issue in ArcSight Logger versions prior to 6.7. | ||
| CVE-2022-26330 | Med | 0.42 | 6.5 | 0.01 | Aug 31, 2022 | Potential vulnerabilities have been identified in Micro Focus ArcSight Logger. The vulnerabilities could be remotely exploited resulting in Information Disclosure, or Self Cross-Site Scripting (XSS). This issue affects: Micro Focus ArcSight Logger versions prior to v7.2.2… | ||
| CVE-2019-3483 | Med | 0.42 | 6.5 | 0.02 | Mar 25, 2019 | Mitigates a potential information leakage issue in ArcSight Logger versions prior to 6.7. | ||
| CVE-2015-6864 | Med | 0.41 | 6.3 | 0.01 | Jan 16, 2016 | HPE ArcSight Logger before 6.1P1 allows remote authenticated users to execute arbitrary code via unspecified input to the (1) Intellicus or (2) client-certificate upload component. | ||
| CVE-2023-24469 | Med | 0.40 | 6.1 | 0.00 | Jun 13, 2023 | Potential Cross-Site Scripting in ArcSight Logger versions prior to 7.3.0 | ||
| CVE-2022-26331 | Med | 0.40 | 6.1 | 0.00 | Aug 31, 2022 | Potential vulnerabilities have been identified in Micro Focus ArcSight Logger. The vulnerabilities could be remotely exploited resulting in Information Disclosure, or Self Cross-Site Scripting (XSS). This issue affects: Micro Focus ArcSight Logger versions prior to v7.2.2… | ||
| CVE-2020-11860 | Med | 0.40 | 6.1 | 0.01 | Nov 17, 2020 | Cross-Site Scripting vulnerability on Micro Focus ArcSight Logger product, affecting all version prior to 7.1.1. The vulnerability could be remotely exploited resulting in Cross-Site Scripting (XSS) | ||
| CVE-2020-11839 | Med | 0.40 | 6.1 | 0.01 | Jun 12, 2020 | Cross Site Scripting (XSS) vulnerability in Micro Focus ArcSight Logger product, affecting all version from 6.6.1 up to version 7.0.1. The vulnerabilities could be remotely exploited resulting in Cross-Site Scripting (XSS) or information disclosure. | ||
| CVE-2019-3480 | Med | 0.40 | 6.1 | 0.01 | Mar 25, 2019 | Mitigates a stored/reflected XSS issue in ArcSight Logger versions prior to 6.7. | ||
| CVE-2020-25834 | Med | 0.35 | 5.4 | 0.01 | Nov 17, 2020 | Cross-Site Scripting vulnerability on Micro Focus ArcSight Logger product, affecting version 7.1. The vulnerability could be remotely exploited resulting in Cross-Site Scripting (XSS). | ||
| CVE-2019-11656 | Med | 0.35 | 5.4 | 0.01 | Oct 4, 2019 | Stored XSS vulnerability in Micro Focus ArcSight Logger, affects versions prior to Logger 6.7.1 HotFix 6.7.1.8262.0. This vulnerability could allow Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'). |
- risk 0.64cvss 9.8epss 0.03
Arbitrary code execution vulnerability on Micro Focus ArcSight Logger product, affecting all version prior to 7.1.1. The vulnerability could be remotely exploited resulting in the execution of arbitrary code.
- risk 0.64cvss 9.8epss 0.07
Mitigates a potential remote code execution issue in ArcSight Logger versions prior to 6.7.
- risk 0.59cvss 9.1epss 0.01
Potential XML External Entity Injection in ArcSight Logger versions prior to 7.3.0.
- risk 0.57cvss 8.8epss 0.00
Cross-Site Request Forgery vulnerability in all Micro Focus ArcSight Logger affecting all product versions below version 7.0. The vulnerability could be exploited to perform CSRF attack.
- risk 0.57cvss 8.8epss 0.02
Unrestricted file upload vulnerability in Micro Focus ArcSight Logger, version 6.7.0 and later. This vulnerability could allow Unrestricted Upload of File with Dangerous type.
- risk 0.53cvss 8.1epss 0.00
Stored Cross-Site Scripting (XSS) vulnerabilities have been identified in OpenText ArcSight Logger. The vulnerabilities could be remotely exploited.
- risk 0.51cvss 7.8epss 0.01
Mitigates a remote code execution issue in ArcSight Logger versions prior to 6.7.
- risk 0.48cvss 7.3epss 0.02
HPE ArcSight Logger before 6.1P1 allows remote attackers to execute arbitrary code via unspecified input to the (1) Intellicus or (2) client-certificate upload component.
- risk 0.46cvss 7.1epss 0.02
Mitigates a XML External Entity Parsing issue in ArcSight Logger versions prior to 6.7.
- risk 0.43cvss 6.5epss 0.04
Mitigates a directory traversal issue in ArcSight Logger versions prior to 6.7.
- risk 0.42cvss 6.5epss 0.01
Potential vulnerabilities have been identified in Micro Focus ArcSight Logger. The vulnerabilities could be remotely exploited resulting in Information Disclosure, or Self Cross-Site Scripting (XSS). This issue affects: Micro Focus ArcSight Logger versions prior to v7.2.2…
- risk 0.42cvss 6.5epss 0.02
Mitigates a potential information leakage issue in ArcSight Logger versions prior to 6.7.
- risk 0.41cvss 6.3epss 0.01
HPE ArcSight Logger before 6.1P1 allows remote authenticated users to execute arbitrary code via unspecified input to the (1) Intellicus or (2) client-certificate upload component.
- risk 0.40cvss 6.1epss 0.00
Potential Cross-Site Scripting in ArcSight Logger versions prior to 7.3.0
- risk 0.40cvss 6.1epss 0.00
Potential vulnerabilities have been identified in Micro Focus ArcSight Logger. The vulnerabilities could be remotely exploited resulting in Information Disclosure, or Self Cross-Site Scripting (XSS). This issue affects: Micro Focus ArcSight Logger versions prior to v7.2.2…
- risk 0.40cvss 6.1epss 0.01
Cross-Site Scripting vulnerability on Micro Focus ArcSight Logger product, affecting all version prior to 7.1.1. The vulnerability could be remotely exploited resulting in Cross-Site Scripting (XSS)
- risk 0.40cvss 6.1epss 0.01
Cross Site Scripting (XSS) vulnerability in Micro Focus ArcSight Logger product, affecting all version from 6.6.1 up to version 7.0.1. The vulnerabilities could be remotely exploited resulting in Cross-Site Scripting (XSS) or information disclosure.
- risk 0.40cvss 6.1epss 0.01
Mitigates a stored/reflected XSS issue in ArcSight Logger versions prior to 6.7.
- risk 0.35cvss 5.4epss 0.01
Cross-Site Scripting vulnerability on Micro Focus ArcSight Logger product, affecting version 7.1. The vulnerability could be remotely exploited resulting in Cross-Site Scripting (XSS).
- risk 0.35cvss 5.4epss 0.01
Stored XSS vulnerability in Micro Focus ArcSight Logger, affects versions prior to Logger 6.7.1 HotFix 6.7.1.8262.0. This vulnerability could allow Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
Page 1 of 2