Vulnerabilities > HP > Arcsight Logger

DATE CVE VULNERABILITY TITLE RISK
2019-10-04 CVE-2019-11656 Cross-site Scripting vulnerability in HP Arcsight Logger
Stored XSS vulnerability in Micro Focus ArcSight Logger, affects versions prior to Logger 6.7.1 HotFix 6.7.1.8262.0.
network
low complexity
hp CWE-79
5.4
2019-10-04 CVE-2019-11655 Unrestricted Upload of File with Dangerous Type vulnerability in HP Arcsight Logger
Unrestricted file upload vulnerability in Micro Focus ArcSight Logger, version 6.7.0 and later.
network
low complexity
hp CWE-434
8.8
2019-07-24 CVE-2019-3485 Cross-site Scripting vulnerability in HP Arcsight Logger
Mitigates a stored cross site scripting issue in ArcSight Logger versions prior to 6.7.1
network
low complexity
hp CWE-79
6.1
2019-03-25 CVE-2019-3484 Unspecified vulnerability in HP Arcsight Logger
Mitigates a remote code execution issue in ArcSight Logger versions prior to 6.7.
local
low complexity
hp
7.8
2019-03-25 CVE-2019-3483 Unspecified vulnerability in HP Arcsight Logger
Mitigates a potential information leakage issue in ArcSight Logger versions prior to 6.7.
network
low complexity
hp
6.5
2019-03-25 CVE-2019-3482 Path Traversal vulnerability in HP Arcsight Logger
Mitigates a directory traversal issue in ArcSight Logger versions prior to 6.7.
network
low complexity
hp CWE-22
6.5
2019-03-25 CVE-2019-3481 XXE vulnerability in HP Arcsight Logger
Mitigates a XML External Entity Parsing issue in ArcSight Logger versions prior to 6.7.
network
low complexity
hp CWE-611
7.1
2019-03-25 CVE-2019-3480 Cross-site Scripting vulnerability in HP Arcsight Logger
Mitigates a stored/reflected XSS issue in ArcSight Logger versions prior to 6.7.
network
low complexity
hp CWE-79
6.1
2019-03-25 CVE-2019-3479 Unspecified vulnerability in HP Arcsight Logger
Mitigates a potential remote code execution issue in ArcSight Logger versions prior to 6.7.
network
low complexity
hp
critical
9.8
2016-01-16 CVE-2015-6864 Improper Input Validation vulnerability in HP Arcsight Logger
HPE ArcSight Logger before 6.1P1 allows remote authenticated users to execute arbitrary code via unspecified input to the (1) Intellicus or (2) client-certificate upload component.
network
low complexity
hp CWE-20
6.3