CVE-2023-24470
published 2023-06-13CVE-2023-24470: Potential XML External Entity Injection in ArcSight Logger versions prior to 7.3.0.
PriorityP349critical9.1CVSS 3.1
AVNACLPRNUINSUCHINAH
EPSS
0.90%
55.7th percentile
Potential XML External Entity Injection in ArcSight Logger versions prior to 7.3.0.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microfocus | arcsight_logger | < 7.3.0 | 7.3.0 |
| microfocus | arcsight_logger | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://portal.microfocus.com/s/article/KM000018224?language=en_UShttps://www.microfocus.com/documentation/arcsight/logger-7.3/logger-7.3-release-notes/https://www.microfocus.com/support/downloads/%2Chttps://portal.microfocus.com/s/article/KM000018224?language=en_UShttps://www.microfocus.com/documentation/arcsight/logger-7.3/logger-7.3-release-notes/https://www.microfocus.com/support/downloads/%2C
2023-06-13
Published