Cross Site Scripting Vulnerability in Micro Focus ArcSight Logger Software
CVE-2020-11839

6.1MEDIUM

Key Information:

Vendor

Microfocus

Vendor
CVE Published:
12 June 2020

What is CVE-2020-11839?

A Cross Site Scripting (XSS) vulnerability exists in Micro Focus ArcSight Logger, which can be exploited remotely by an attacker. This vulnerability impacts all versions from 6.6.1 through 7.0.1, potentially leading to unauthorized scripting within the user's interface or information disclosure. Immediate mitigation actions should be taken to secure affected installations.

Affected Version(s)

ArcSight Logger. All version from 6.6.1 up to 7.0.1

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.