First published: Wed Aug 08 2012(Updated: )
Cross-site scripting (XSS) vulnerability in the import functionality in HP ArcSight Connector appliance 6.2.0.6244.0 and ArcSight Logger appliance 5.2.0.6288.0 allows remote attackers to inject arbitrary web script or HTML via a crafted file.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
HP ArcSight Connector Appliance Firmware | =6.0.0.60023.2 | |
HP ArcSight Connector Appliance Firmware | =6.2.0.6244.0 | |
HP ArcSight Connector Appliance Firmware | =c1400 | |
HP ArcSight Connector Appliance Firmware | =c3400 | |
HP ArcSight Connector Appliance Firmware | =c5400 | |
HP ArcSight Logger Appliance Firmware | =5.2.0.6288.0 | |
HP ArcSight Logger Appliance Firmware | =l7400-san |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-2960 is classified as a medium severity cross-site scripting vulnerability.
To fix CVE-2012-2960, users should apply the latest firmware updates for the affected HP ArcSight products.
CVE-2012-2960 affects HP ArcSight Connector appliance versions 6.2.0.6244.0 and 6.0.0.60023.2, as well as ArcSight Logger appliance version 5.2.0.6288.0.
CVE-2012-2960 is a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary web scripts.
Yes, CVE-2012-2960 can be exploited remotely by attackers through crafted files.