Vulnerabilities > CVE-2014-7885 - Unspecified vulnerability in Microfocus Arcsight Enterprise Security Manager 5.6/6.0/6.5
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN microfocus
nessus
Summary
Multiple unspecified vulnerabilities in HP ArcSight Enterprise Security Manager (ESM) before 6.8c have unknown impact and remote attack vectors.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 3 |
Nessus
NASL family | Misc. |
NASL id | ARCSIGHT_ESM_68C.NASL |
description | According to its self-reported version number, the version of HP ArcSight Enterprise Security Manager (ESM) installed on the remote host is prior to 6.5.1.1845.0 (6.5c SP1 P1) or 6.8.0.1896 (6.8c). It is, therefore, affected by multiple vulnerabilities : - A cross-site scripting (XSS) vulnerability exists due to a failure to validate input to tooltips before returning it to the user. A remote attacker can exploit this, via a specially crafted request, to execute arbitrary script code in a user |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 82848 |
published | 2015-04-17 |
reporter | This script is Copyright (C) 2015-2019 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/82848 |
title | HP ArcSight ESM < 6.5c SP1 P1 / 6.8c Multiple Vulnerabilities |
code |
|
References
- http://www.kb.cert.org/vuls/id/868948
- http://www.kb.cert.org/vuls/id/868948
- http://www.securitytracker.com/id/1031921
- http://www.securitytracker.com/id/1031921
- https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04562193
- https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04562193
- https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04562193
- https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04562193