
CVE-2019-11655
https://notcve.org/view.php?id=CVE-2019-11655
04 Oct 2019 — Unrestricted file upload vulnerability in Micro Focus ArcSight Logger, version 6.7.0 and later. This vulnerability could allow Unrestricted Upload of File with Dangerous type. Vulnerabilidad de carga de archivos sin restricciones en Micro Focus ArcSight Logger, versión 6.7.0 y posteriores. Esta vulnerabilidad podría permitir la Carga Irrestricta de Archivos con tipo Peligroso. • https://community.microfocus.com/t5/ArcSight-Announcements/ArcSight-Logger-Fix-for-Security-Vulnerability/td-p/2699569 • CWE-434: Unrestricted Upload of File with Dangerous Type •

CVE-2019-3485 – ArcSight Logger stored cross site script issue in version prior to 6.7.1
https://notcve.org/view.php?id=CVE-2019-3485
24 Jul 2019 — Mitigates a stored cross site scripting issue in ArcSight Logger versions prior to 6.7.1 Mitiga un problema de Cross-Site Scripting (XSS) persistente en ArcSight Logger, en versiones anteriores a la 6.7.1. • http://www.securityfocus.com/bid/109363 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2019-3484
https://notcve.org/view.php?id=CVE-2019-3484
25 Mar 2019 — Mitigates a remote code execution issue in ArcSight Logger versions prior to 6.7. Mitiga un problema de ejecución remota de código en ArcSight Logger, en versiones anteriores a la 6.7. • https://softwaresupport.softwaregrp.com/doc/KM03355866 •

CVE-2019-3483
https://notcve.org/view.php?id=CVE-2019-3483
25 Mar 2019 — Mitigates a potential information leakage issue in ArcSight Logger versions prior to 6.7. Mitiga un potencial problema de fuga de información en ArcSight Logger, en versiones anteriores a la 6.7. • https://softwaresupport.softwaregrp.com/doc/KM03355866 •

CVE-2019-3482
https://notcve.org/view.php?id=CVE-2019-3482
25 Mar 2019 — Mitigates a directory traversal issue in ArcSight Logger versions prior to 6.7. Mitiga un problema de salto de directorio en ArcSight Logger, en versiones anteriores a la 6.7. • https://softwaresupport.softwaregrp.com/doc/KM03355866 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2019-3481
https://notcve.org/view.php?id=CVE-2019-3481
25 Mar 2019 — Mitigates a XML External Entity Parsing issue in ArcSight Logger versions prior to 6.7. Mitiga un problema de análisis de entidades externas XML en ArcSight Logger, en versiones anteriores a la 6.7. • https://softwaresupport.softwaregrp.com/doc/KM03355866 • CWE-611: Improper Restriction of XML External Entity Reference •

CVE-2019-3480
https://notcve.org/view.php?id=CVE-2019-3480
25 Mar 2019 — Mitigates a stored/reflected XSS issue in ArcSight Logger versions prior to 6.7. Mitiga un problema de XSS persistente/reflejado en ArcSight Logger, en versiones anteriores a la 6.7. • https://softwaresupport.softwaregrp.com/doc/KM03355866 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2019-3479
https://notcve.org/view.php?id=CVE-2019-3479
25 Mar 2019 — Mitigates a potential remote code execution issue in ArcSight Logger versions prior to 6.7. Mitiga un potencial problema de ejecución remota de código en ArcSight Logger, en versiones anteriores a la 6.7. • https://softwaresupport.softwaregrp.com/doc/KM03355866 •

CVE-2015-6863 – HP Security Bulletin HPSBGN03532 1
https://notcve.org/view.php?id=CVE-2015-6863
13 Jan 2016 — HPE ArcSight Logger before 6.1P1 allows remote attackers to execute arbitrary code via unspecified input to the (1) Intellicus or (2) client-certificate upload component. HPE ArcSight Logger en versiones anteriores a 6.1P1 permite a atacantes remotos ejecutar código arbitrario a través de una entrada no especificada al componente de subida (1) Intellicus o (2) client-certificate. Potential security vulnerabilities have been identified in Intellicus and the client certificate upload components of HPE ArcSigh... • https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04941487 • CWE-20: Improper Input Validation •

CVE-2015-6864 – HP Security Bulletin HPSBGN03532 1
https://notcve.org/view.php?id=CVE-2015-6864
13 Jan 2016 — HPE ArcSight Logger before 6.1P1 allows remote authenticated users to execute arbitrary code via unspecified input to the (1) Intellicus or (2) client-certificate upload component. HPE ArcSight Logger en versiones anteriores a 6.1P1 permite a usuarios remotos autenticados ejecutar código arbitrario a través de una entrada no especificada al componente de subida (1) Intellicus o (2) client-certificat. Potential security vulnerabilities have been identified in Intellicus and the client certificate upload comp... • https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04941487 • CWE-20: Improper Input Validation •