20 results (0.007 seconds)

CVSS: 5.4EPSS: 0%CPEs: 2EXPL: 0

04 Oct 2019 — Stored XSS vulnerability in Micro Focus ArcSight Logger, affects versions prior to Logger 6.7.1 HotFix 6.7.1.8262.0. This vulnerability could allow Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'). Una vulnerabilidad de tipo XSS almacenado en Micro Focus ArcSight Logger afecta las versiones anteriores a Logger versión 6.7.1 HotFix versión 6.7.1.8262.0. Esta vulnerabilidad podría permitir la Neutralización Inapropiada de la Entrada Durante la Generación de Páginas Web ("Cr... • https://community.microfocus.com/t5/ArcSight-Announcements/ArcSight-Logger-Fix-for-Security-Vulnerability/td-p/2699569 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 0

04 Oct 2019 — Unrestricted file upload vulnerability in Micro Focus ArcSight Logger, version 6.7.0 and later. This vulnerability could allow Unrestricted Upload of File with Dangerous type. Vulnerabilidad de carga de archivos sin restricciones en Micro Focus ArcSight Logger, versión 6.7.0 y posteriores. Esta vulnerabilidad podría permitir la Carga Irrestricta de Archivos con tipo Peligroso. • https://community.microfocus.com/t5/ArcSight-Announcements/ArcSight-Logger-Fix-for-Security-Vulnerability/td-p/2699569 • CWE-434: Unrestricted Upload of File with Dangerous Type •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

24 Jul 2019 — Mitigates a stored cross site scripting issue in ArcSight Logger versions prior to 6.7.1 Mitiga un problema de Cross-Site Scripting (XSS) persistente en ArcSight Logger, en versiones anteriores a la 6.7.1. • http://www.securityfocus.com/bid/109363 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

25 Mar 2019 — Mitigates a remote code execution issue in ArcSight Logger versions prior to 6.7. Mitiga un problema de ejecución remota de código en ArcSight Logger, en versiones anteriores a la 6.7. • https://softwaresupport.softwaregrp.com/doc/KM03355866 •

CVSS: 6.8EPSS: 0%CPEs: 1EXPL: 0

25 Mar 2019 — Mitigates a potential information leakage issue in ArcSight Logger versions prior to 6.7. Mitiga un potencial problema de fuga de información en ArcSight Logger, en versiones anteriores a la 6.7. • https://softwaresupport.softwaregrp.com/doc/KM03355866 •

CVSS: 6.8EPSS: 1%CPEs: 1EXPL: 0

25 Mar 2019 — Mitigates a directory traversal issue in ArcSight Logger versions prior to 6.7. Mitiga un problema de salto de directorio en ArcSight Logger, en versiones anteriores a la 6.7. • https://softwaresupport.softwaregrp.com/doc/KM03355866 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

25 Mar 2019 — Mitigates a XML External Entity Parsing issue in ArcSight Logger versions prior to 6.7. Mitiga un problema de análisis de entidades externas XML en ArcSight Logger, en versiones anteriores a la 6.7. • https://softwaresupport.softwaregrp.com/doc/KM03355866 • CWE-611: Improper Restriction of XML External Entity Reference •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

25 Mar 2019 — Mitigates a stored/reflected XSS issue in ArcSight Logger versions prior to 6.7. Mitiga un problema de XSS persistente/reflejado en ArcSight Logger, en versiones anteriores a la 6.7. • https://softwaresupport.softwaregrp.com/doc/KM03355866 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 9.8EPSS: 7%CPEs: 1EXPL: 0

25 Mar 2019 — Mitigates a potential remote code execution issue in ArcSight Logger versions prior to 6.7. Mitiga un potencial problema de ejecución remota de código en ArcSight Logger, en versiones anteriores a la 6.7. • https://softwaresupport.softwaregrp.com/doc/KM03355866 •

CVSS: 7.5EPSS: 2%CPEs: 1EXPL: 0

13 Jan 2016 — HPE ArcSight Logger before 6.1P1 allows remote attackers to execute arbitrary code via unspecified input to the (1) Intellicus or (2) client-certificate upload component. HPE ArcSight Logger en versiones anteriores a 6.1P1 permite a atacantes remotos ejecutar código arbitrario a través de una entrada no especificada al componente de subida (1) Intellicus o (2) client-certificate. Potential security vulnerabilities have been identified in Intellicus and the client certificate upload components of HPE ArcSigh... • https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04941487 • CWE-20: Improper Input Validation •