Vulnerability Description
HPE ArcSight ESM 5.x before 5.6, 6.0, 6.5.x before 6.5C SP1 Patch 2, and 6.8c before P1, and ArcSight ESM Express before 6.9.1, allows remote authenticated users to conduct unspecified "file download" attacks via unknown vectors.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microfocus | Arcsight Enterprise Security Manager | >= 5.0, <= 5.6 |
References
- http://www.securitytracker.com/id/1035282Third Party AdvisoryVDB Entry
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-cPatchVendor Advisory
- http://www.securitytracker.com/id/1035282Third Party AdvisoryVDB Entry
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-cPatchVendor Advisory
FAQ
What is CVE-2016-1991?
CVE-2016-1991 is a vulnerability with a CVSS score of 8.0 (HIGH). HPE ArcSight ESM 5.x before 5.6, 6.0, 6.5.x before 6.5C SP1 Patch 2, and 6.8c before P1, and ArcSight ESM Express before 6.9.1, allows remote authenticated users to conduct unspecified "file download"...
How severe is CVE-2016-1991?
CVE-2016-1991 has been rated HIGH with a CVSS base score of 8.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-1991?
Check the references section above for vendor advisories and patch information. Affected products include: Microfocus Arcsight Enterprise Security Manager.