Cross Site Scripting Vulnerability in Micro Focus ArcSight ESM Product
CVE-2020-9522

6.1MEDIUM

Key Information:

Vendor

Microfocus

Vendor
CVE Published:
16 June 2020

What is CVE-2020-9522?

A Cross Site Scripting (XSS) vulnerability exists in the Micro Focus ArcSight Enterprise Security Manager (ESM) product, potentially allowing attackers to execute malicious scripts in the context of a user's session. This vulnerability impacts versions 7.0.x, 7.2, and 7.2.1. If exploited, it can lead to unauthorized access to sensitive information and may compromise user data integrity.

Affected Version(s)

ArcSight Enterprise Security Manager (ESM). 7.0.x, 7.2 and 7.2.1

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.