CVE-2019-11656
- EPSS 0.18%
- Published 04.10.2019 20:15:11
- Last modified 21.11.2024 04:21:32
Stored XSS vulnerability in Micro Focus ArcSight Logger, affects versions prior to Logger 6.7.1 HotFix 6.7.1.8262.0. This vulnerability could allow Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
CVE-2019-11655
- EPSS 0.51%
- Published 04.10.2019 20:15:11
- Last modified 21.11.2024 04:21:32
Unrestricted file upload vulnerability in Micro Focus ArcSight Logger, version 6.7.0 and later. This vulnerability could allow Unrestricted Upload of File with Dangerous type.
CVE-2019-3485
- EPSS 0.3%
- Published 24.07.2019 16:15:12
- Last modified 21.11.2024 04:42:07
Mitigates a stored cross site scripting issue in ArcSight Logger versions prior to 6.7.1
CVE-2019-3484
- EPSS 0.45%
- Published 25.03.2019 17:29:01
- Last modified 21.11.2024 04:42:07
Mitigates a remote code execution issue in ArcSight Logger versions prior to 6.7.
CVE-2019-3483
- EPSS 0.35%
- Published 25.03.2019 17:29:01
- Last modified 21.11.2024 04:42:07
Mitigates a potential information leakage issue in ArcSight Logger versions prior to 6.7.
CVE-2019-3482
- EPSS 2.08%
- Published 25.03.2019 17:29:00
- Last modified 21.11.2024 04:42:07
Mitigates a directory traversal issue in ArcSight Logger versions prior to 6.7.
CVE-2019-3481
- EPSS 0.43%
- Published 25.03.2019 17:29:00
- Last modified 21.11.2024 04:42:07
Mitigates a XML External Entity Parsing issue in ArcSight Logger versions prior to 6.7.
CVE-2019-3480
- EPSS 0.36%
- Published 25.03.2019 17:29:00
- Last modified 21.11.2024 04:42:07
Mitigates a stored/reflected XSS issue in ArcSight Logger versions prior to 6.7.
CVE-2019-3479
- EPSS 7.43%
- Published 25.03.2019 17:29:00
- Last modified 21.11.2024 04:42:06
Mitigates a potential remote code execution issue in ArcSight Logger versions prior to 6.7.
CVE-2015-6864
- EPSS 0.67%
- Published 16.01.2016 05:59:01
- Last modified 12.04.2025 10:46:40
HPE ArcSight Logger before 6.1P1 allows remote authenticated users to execute arbitrary code via unspecified input to the (1) Intellicus or (2) client-certificate upload component.