Cross-Site Scripting Vulnerability in Micro Focus ArcSight Logger Product
CVE-2020-25834

5.4MEDIUM

Key Information:

Vendor
CVE Published:
17 November 2020

What is CVE-2020-25834?

A Cross-Site Scripting vulnerability exists in the Micro Focus ArcSight Logger, impacting version 7.1. This security flaw allows attackers to execute malicious scripts in the context of the user's session, potentially leading to unauthorized access or data theft. The vulnerability can be exploited remotely, making it critical for users to apply patches and security updates to mitigate risks associated with this flaw.

Affected Version(s)

ArcSight Logger 7.1

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.