CVE-2015-6863

Severity
7.3HIGH
EPSS
2.5%
top 14.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 16
Latest updateMay 17

Description

HPE ArcSight Logger before 6.1P1 allows remote attackers to execute arbitrary code via unspecified input to the (1) Intellicus or (2) client-certificate upload component.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:LExploitability: 3.9 | Impact: 3.4

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-hwg3-34cw-8x3q: HPE ArcSight Logger before 62022-05-17
CVEList
CVE-2015-6863: HPE ArcSight Logger before 62016-01-16
CVE-2015-6863 (HIGH CVSS 7.3) | HPE ArcSight Logger before 6.1P1 al | cvebase.io