Hp Arcsight Connector Appliance vulnerabilities
5 known vulnerabilities affecting hp/arcsight_connector_appliance.
Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM4
Vulnerabilities
Page 1 of 1
CVE-2015-6030HIGHCVSS 7.2≤ 6.4.0.6881.32015-11-04
CVE-2015-6030 [HIGH] CWE-264 CVE-2015-6030: HP ArcSight Logger 6.0.0.7307.1, ArcSight Command Center 6.8.0.1896.0, and ArcSight Connector Applia
HP ArcSight Logger 6.0.0.7307.1, ArcSight Command Center 6.8.0.1896.0, and ArcSight Connector Appliance 6.4.0.6881.3 use the root account to execute files owned by the arcsight user, which might allow local users to gain privileges by leveraging arcsight account access.
nvd
CVE-2012-5198MEDIUMCVSS 5.0vc1400vc3400+1 more2013-02-16
CVE-2012-5198 [MEDIUM] CVE-2012-5198: Unspecified vulnerability in HP ArcSight Connector Appliance before 6.3 and ArcSight Logger 5.2 and
Unspecified vulnerability in HP ArcSight Connector Appliance before 6.3 and ArcSight Logger 5.2 and earlier allows remote attackers to obtain sensitive information via unknown vectors.
nvd
CVE-2012-3286MEDIUMCVSS 6.5vc1400vc3400+1 more2013-02-16
CVE-2012-3286 [MEDIUM] CVE-2012-3286: Unspecified vulnerability in HP ArcSight Connector Appliance 6.3 and earlier and ArcSight Logger 5.2
Unspecified vulnerability in HP ArcSight Connector Appliance 6.3 and earlier and ArcSight Logger 5.2 and earlier allows remote authenticated users to obtain sensitive information, modify data, or cause a denial of service via unknown vectors.
nvd
CVE-2012-5199MEDIUMCVSS 6.8vc1400vc3400+1 more2013-02-16
CVE-2012-5199 [MEDIUM] CVE-2012-5199: Unspecified vulnerability in HP ArcSight Connector Appliance 6.3 and earlier and ArcSight Logger 5.2
Unspecified vulnerability in HP ArcSight Connector Appliance 6.3 and earlier and ArcSight Logger 5.2 and earlier allows remote authenticated users to execute arbitrary code via unknown vectors.
nvd
CVE-2012-2960MEDIUMCVSS 4.3vc1400vc3400+1 more2012-08-08
CVE-2012-2960 [MEDIUM] CWE-79 CVE-2012-2960: Cross-site scripting (XSS) vulnerability in the import functionality in HP ArcSight Connector applia
Cross-site scripting (XSS) vulnerability in the import functionality in HP ArcSight Connector appliance 6.2.0.6244.0 and ArcSight Logger appliance 5.2.0.6288.0 allows remote attackers to inject arbitrary web script or HTML via a crafted file.
nvd