CVE-2013-4815: XSS
Cross-site scripting (XSS) vulnerability in the web interface in HP ArcSight Enterprise Security Manager (ESM) before 5.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4815?
CVE-2013-4815 is classified as a medium severity vulnerability due to its potential for allowing cross-site scripting attacks.
How do I fix CVE-2013-4815?
To mitigate CVE-2013-4815, upgrade to HP ArcSight Enterprise Security Manager version 5.5 or later.
What kind of attacks does CVE-2013-4815 facilitate?
CVE-2013-4815 allows remote attackers to perform cross-site scripting (XSS) attacks by injecting arbitrary web scripts or HTML.
Which versions of HP ArcSight Enterprise Security Manager are affected by CVE-2013-4815?
CVE-2013-4815 affects HP ArcSight Enterprise Security Manager versions up to and including 5.2.
Is CVE-2013-4815 easy to exploit?
Exploitation of CVE-2013-4815 may be straightforward for attackers with knowledge of the affected web interface.