Insufficient Access Control in ArcSight ESM and ESM Express
CVE-2017-13987
6.5MEDIUM
Key Information:
- Vendor
HP
- Vendor
- CVE Published:
- 30 September 2017
What is CVE-2017-13987?
An insufficient access control vulnerability exists in ArcSight ESM and ArcSight ESM Express, impacting specific versions that permit unauthorized users to download log files. This exposure can lead to potential information leaks, putting sensitive data at risk. Users running ArcSight ESM versions prior to 6.9.1c Patch 4 and ArcSight ESM Express version 6.11.0 Patch 1 should take precautions to mitigate unauthorized access.