|
255401
|
5.3 |
MEDIUM
Network
|
hp
|
arcsight_enterprise_security_manager arcsight_enterprise_security_manager_express
|
An information leakage vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows disclosure of product license features.
|
CWE-200
Information Exposure
|
CVE-2017-13991
|
2024-11-21 12:11 |
2017-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255402
|
5.3 |
MEDIUM
Network
|
hp
|
arcsight_enterprise_security_manager arcsight_enterprise_security_manager_express
|
An information leakage vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows disclosure of Apache Tomcat application server version.
|
CWE-200
Information Exposure
|
CVE-2017-13990
|
2024-11-21 12:11 |
2017-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255403
|
8.1 |
HIGH
Network
|
hp
|
arcsight_enterprise_security_manager arcsight_enterprise_security_manager_express
|
An improper access control vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows unauthorized users to retrieve or modify storage i…
|
NVD-CWE-noinfo
|
CVE-2017-13989
|
2024-11-21 12:11 |
2017-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255404
|
6.5 |
MEDIUM
Network
|
hp
|
arcsight_enterprise_security_manager arcsight_enterprise_security_manager_express
|
An improper access control vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows unauthorized users to alter the maximum size of st…
|
NVD-CWE-noinfo
|
CVE-2017-13988
|
2024-11-21 12:11 |
2017-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255405
|
6.5 |
MEDIUM
Network
|
hp
|
arcsight_enterprise_security_manager arcsight_enterprise_security_manager_express
|
An insufficient access control vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows an unauthorized user to download log files.
|
NVD-CWE-noinfo
|
CVE-2017-13987
|
2024-11-21 12:11 |
2017-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255406
|
6.1 |
MEDIUM
Network
|
hp
|
arcsight_enterprise_security_manager arcsight_enterprise_security_manager_express
|
A reflected Cross-Site Scripting(XSS) vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows for unintended information when a speci…
|
CWE-79
Cross-site Scripting
|
CVE-2017-13986
|
2024-11-21 12:11 |
2017-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255407
|
6.5 |
MEDIUM
Network
|
hp
|
bsm_platform_application_performance_management_system_health
|
An authentication vulnerability in HPE BSM Platform Application Performance Management System Health product versions 9.26, 9.30 and 9.40, allows remote users to traverse directory leading to disclos…
|
CWE-22
Path Traversal
|
CVE-2017-13985
|
2024-11-21 12:11 |
2017-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255408
|
6.5 |
MEDIUM
Network
|
hp
|
bsm_platform_application_performance_management_system_health
|
An authentication vulnerability in HPE BSM Platform Application Performance Management System Health product versions 9.26, 9.30 and 9.40, allows remote users to delete arbitrary files via servlet di…
|
CWE-287
Improper Authentication
|
CVE-2017-13984
|
2024-11-21 12:11 |
2017-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255409
|
9.8 |
CRITICAL
Network
|
hp
|
bsm_platform_application_performance_management_system_health
|
An authentication vulnerability in HPE BSM Platform Application Performance Management System Health product versions 9.26, 9.30 and 9.40, allows remote users to bypass authentication.
|
CWE-287
Improper Authentication
|
CVE-2017-13983
|
2024-11-21 12:11 |
2017-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255410
|
8.8 |
HIGH
Network
|
hp
|
bsm_platform_application_performance_management_system_health
|
A directory traversal vulnerability in HPE BSM Platform Application Performance Management System Health product versions 9.26, 9.30 and 9.40, allows users to upload unrestricted files.
|
CWE-22 CWE-434
Path Traversal Unrestricted Upload of File with Dangerous Type
|
CVE-2017-13982
|
2024-11-21 12:11 |
2017-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|