Cross-Site Scripting Vulnerability in HP ArcSight Connector and Logger Products
CVE-2012-2960
Currently unrated
Key Information:
- Vendor
- HP
- Vendor
- CVE Published:
- 8 August 2012
Summary
A Cross-Site Scripting (XSS) vulnerability exists in the import functionality of HP ArcSight Connector appliance and ArcSight Logger appliance. Attackers can exploit this vulnerability by crafting a malicious file that, when imported, may allow arbitrary web scripts or HTML to be injected into the application. This could lead to unauthorized actions being executed on behalf of authenticated users, potentially compromising sensitive data and user accounts.
References
Timeline
Vulnerability published
Vulnerability Reserved