VYPR
Vendor

ArcSight

Products
2
CVEs
10
Across products
10
Status
Private

Products

2

Recent CVEs

10
  • CVE-2019-3479CriMar 25, 2019
    risk 0.64cvss 9.8epss 0.07

    Mitigates a potential remote code execution issue in ArcSight Logger versions prior to 6.7.

  • CVE-2019-3484HigMar 25, 2019
    risk 0.51cvss 7.8epss 0.01

    Mitigates a remote code execution issue in ArcSight Logger versions prior to 6.7.

  • CVE-2019-3481HigMar 25, 2019
    risk 0.46cvss 7.1epss 0.02

    Mitigates a XML External Entity Parsing issue in ArcSight Logger versions prior to 6.7.

  • CVE-2019-3482MedMar 25, 2019
    risk 0.43cvss 6.5epss 0.04

    Mitigates a directory traversal issue in ArcSight Logger versions prior to 6.7.

  • CVE-2019-3483MedMar 25, 2019
    risk 0.42cvss 6.5epss 0.02

    Mitigates a potential information leakage issue in ArcSight Logger versions prior to 6.7.

  • CVE-2017-13988MedSep 30, 2017
    risk 0.42cvss 6.5epss 0.01

    An improper access control vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows unauthorized users to alter the maximum size of storage groups and enable/disable the setting for the 'follow schedule' function.

  • CVE-2017-13987MedSep 30, 2017
    risk 0.42cvss 6.5epss 0.01

    An insufficient access control vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows an unauthorized user to download log files.

  • CVE-2019-3480MedMar 25, 2019
    risk 0.40cvss 6.1epss 0.01

    Mitigates a stored/reflected XSS issue in ArcSight Logger versions prior to 6.7.

  • CVE-2017-13986MedSep 30, 2017
    risk 0.40cvss 6.1epss 0.01

    A reflected Cross-Site Scripting(XSS) vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows for unintended information when a specific URL is sent to the system.

  • CVE-2017-13991MedSep 30, 2017
    risk 0.35cvss 5.3epss 0.01

    An information leakage vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows disclosure of product license features.