Microfocus Arcsight Management Center vulnerabilities

8 known vulnerabilities affecting microfocus/arcsight_management_center.

Total CVEs
8
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH4MEDIUM4

Vulnerabilities

Page 1 of 1
CVE-2024-9841HIGHCVSS 7.0fixed in 3.2.5v3.2.52024-11-08
CVE-2024-9841 [HIGH] CWE-79 CVE-2024-9841: A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in OpenText ArcSight Manage A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in OpenText ArcSight Management Center and ArcSight Platform. The vulnerability could be remotely exploited.
nvd
CVE-2020-25835MEDIUMCVSS 5.4≥ 2.9.0, < 2.9.62023-12-09
CVE-2020-25835 [MEDIUM] CWE-79 CVE-2020-25835: A potential vulnerability has been identified in Micro Focus ArcSight Management Center. The vulnera A potential vulnerability has been identified in Micro Focus ArcSight Management Center. The vulnerability could be remotely exploited resulting in stored Cross-Site Scripting (XSS).
nvd
CVE-2023-32267HIGHCVSS 8.8fixed in 3.2.12023-08-11
CVE-2023-32267 [HIGH] CVE-2023-32267: A potential vulnerability has been identified in OpenText / Micro Focus ArcSight Management Center. A potential vulnerability has been identified in OpenText / Micro Focus ArcSight Management Center. The vulnerability could be remotely exploited.
nvd
CVE-2020-11848HIGHCVSS 7.5fixed in 2.9.5vAll version prior to version 2.9.52020-08-19
CVE-2020-11848 [HIGH] CVE-2020-11848: Denial of service vulnerability on Micro Focus ArcSight Management Center. Affecting all versions pr Denial of service vulnerability on Micro Focus ArcSight Management Center. Affecting all versions prior to version 2.9.5. The vulnerability could cause the server to become unavailable, causing a denial of service.
cvelistv5nvd
CVE-2020-11841MEDIUMCVSS 4.3≥ 2.7.0, < 2.9.4v2.6.12020-06-16
CVE-2020-11841 [MEDIUM] CVE-2020-11841: Unauthorized information disclosure vulnerability in Micro Focus ArcSight Management Center product, Unauthorized information disclosure vulnerability in Micro Focus ArcSight Management Center product, Affecting versions 2.6.1, 2.7.x, 2.8.x, 2.9.x prior to 2.9.4. The vulnerabilities could be remotely exploited resulting unauthorized information disclosure.
nvd
CVE-2020-11838MEDIUMCVSS 5.4≥ 2.7.0, < 2.9.4v2.6.12020-06-16
CVE-2020-11838 [MEDIUM] CWE-79 CVE-2020-11838: Cross Site Scripting (XSS) vulnerability in Micro Focus ArcSight Management Center product, Affectin Cross Site Scripting (XSS) vulnerability in Micro Focus ArcSight Management Center product, Affecting versions 2.6.1, 2.7.x, 2.8.x, 2.9.x prior to 2.9.4. The vulnerabilities could be remotely exploited resulting in Cross-Site Scripting (XSS) or information disclosure.
nvd
CVE-2020-11840MEDIUMCVSS 4.3≥ 2.7.0, < 2.9.4v2.6.12020-06-16
CVE-2020-11840 [MEDIUM] CVE-2020-11840: Unauthorized information disclosure vulnerability in Micro Focus ArcSight Management Center product, Unauthorized information disclosure vulnerability in Micro Focus ArcSight Management Center product, Affecting versions 2.6.1, 2.7.x, 2.8.x, 2.9.x prior to 2.9.4. The vulnerabilities could be remotely exploited resulting unauthorized information disclosure.
nvd
CVE-2018-6504HIGHCVSS 8.8fixed in 2.812018-09-20
CVE-2018-6504 [HIGH] CWE-352 CVE-2018-6504: A potential Cross-Site Request Forgery (CSRF) vulnerability has been identified in ArcSight Manageme A potential Cross-Site Request Forgery (CSRF) vulnerability has been identified in ArcSight Management Center (ArcMC) in all versions prior to 2.81. This vulnerability could be exploited to allow for Cross-Site Request Forgery (CSRF).
nvd