PT-2017-13183 · Arcsight · Arcsight Esm Express+1
Published
2017-09-29
·
Updated
2019-10-03
·
CVE-2017-13989
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
ArcSight ESM versions prior to 6.9.1c Patch 4
ArcSight ESM versions prior to 6.11.0 Patch 1
ArcSight ESM Express versions prior to 6.9.1c Patch 4
ArcSight ESM Express versions prior to 6.11.0 Patch 1
Description
The issue is related to improper access control, allowing unauthorized users to retrieve or modify storage information.
Recommendations
For ArcSight ESM and ArcSight ESM Express versions prior to 6.9.1c Patch 4, update to 6.9.1c Patch 4 or later.
For ArcSight ESM and ArcSight ESM Express versions prior to 6.11.0 Patch 1, update to 6.11.0 Patch 1 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Arcsight Esm
Arcsight Esm Express