Cross-Site Scripting Vulnerability in Micro Focus ArcSight Enterprise Security Manager
CVE-2021-38126

6.1MEDIUM

What is CVE-2021-38126?

Micro Focus ArcSight Enterprise Security Manager has identified potential vulnerabilities in versions 7.4.x and 7.5.x that allow attackers to exploit the system remotely. These vulnerabilities can lead to Cross-Site Scripting (XSS) attacks, which may allow unauthorized users to inject malicious scripts into web pages viewed by other users, potentially compromising sensitive data and system integrity. Proper patches and mitigations should be applied to safeguard against these types of attacks.

Affected Version(s)

ArcSight Enterprise Security Manager (ESM) Micro Focus ArcSight ESM 7.4.x and 7.5.x

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.