First published: Tue Jul 19 2011(Updated: )
Windows Event Log SmartConnector in HP ArcSight Connector Appliance before 6.1 uses world-writable permissions for exported report files, which allows local users to change or delete log data by modifying a file, a different vulnerability than CVE-2011-0770.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Hp Arcsight C5400 Appliance | ||
Hp Arcsight C5200 Appliance | ||
Hp Arcsight C3200 Appliance | ||
Hp Arcsight C3400 Appliance | ||
Hp Arcsight C1300 Appliance | ||
Hp Arcsight C1000 Appliance | ||
Hp Windows Event Log Smartconnector | <=6.0.0.60023.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-2779 is considered a medium severity vulnerability due to the risk of unauthorized modification or deletion of log data.
To fix CVE-2011-2779, apply the latest security updates from HP that address permission settings for exported report files.
CVE-2011-2779 affects various HP ArcSight Connector Appliances including the C5400, C5200, C3200, C3400, C1300, C1000 models and the Windows Event Log SmartConnector versions up to 6.0.0.60023.2.
CVE-2011-2779 allows local users to potentially alter or erase important log data, which can hinder security auditing and incident response.
A possible workaround for CVE-2011-2779 is to restrict local user access to the affected log files until a patch can be applied.