Vulnerability Bulletins |
Vulnerabilidades en HP ArcSight Conector Appliance y Logger |
|
Vulnerability classification |
|
| Property | Value |
| Confidence level | Oficial |
| Impact | Obtener acceso |
| Dificulty | Avanzado |
| Required attacker level | Acceso remoto sin cuenta a un servicio exotico |
System information |
|
| Property | Value |
| Affected manufacturer | Comercial Software |
| Affected software | HP ArcSight Conector Appliance (v6.3 y anteriores) y Logger (v5.2 y anteriores) |
Description |
|
| Se han descubierto varias vulnerabilidades en HP ArcSight Conector Appliance (v6.3 y anteriores) y Logger (v5.2 y anteriores), que podrían ser explotadas remotamente para permitir la divulgación de información, inyección de comandos y ataques cross-site scripting (XSS). | |
Solution |
|
| HP ha publiado HP ArcSight Conector Appliance v6.4 y HP ArcSight Logger v5.3 para resolver estos problemas. Contactar con el soporte técnico de HP para recibir actualizaciones. | |
Standar resources |
|
| Property | Value |
| CVE |
CVE-2012-2960 CVE-2012-3286 CVE-2012-5198 CVE-2012-5199 |
| BID | |
Other resources |
|
| HPSBMU02836 SSRT101056 rev.1 - HP ArcSight Connector Appliance and ArcSight Logger, Remote Disclosure of Information, Command Injection, Cross-Site Scripting (XSS) | |
Version history |
||
| Version | Comments | Date |
| 1.0 | Aviso emitido | 2013-02-26 |






