Cross-Site Scripting Vulnerability in HP ArcSight Connector and Logger Products
CVE-2012-2960

Currently unrated

Key Information:

Vendor
HP
Vendor
CVE Published:
8 August 2012

Summary

A Cross-Site Scripting (XSS) vulnerability exists in the import functionality of HP ArcSight Connector appliance and ArcSight Logger appliance. Attackers can exploit this vulnerability by crafting a malicious file that, when imported, may allow arbitrary web scripts or HTML to be injected into the application. This could lead to unauthorized actions being executed on behalf of authenticated users, potentially compromising sensitive data and user accounts.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.