File Download Vulnerability in HPE ArcSight ESM Products
CVE-2016-1991

8HIGH

Key Information:

Vendor

Microfocus

Vendor
CVE Published:
16 March 2016

What is CVE-2016-1991?

HPE ArcSight ESM and ArcSight ESM Express products are susceptible to a vulnerability that allows remote authenticated users to perform unauthorized file download attacks. This issue arises from unspecified vectors and could lead to the unauthorized access of sensitive files and data, posing a significant risk to impacted systems.

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.