First published: Wed Nov 04 2015(Updated: )
The CWSAPI SOAP service in HP ArcSight SmartConnectors before 7.1.6 has a hardcoded password, which makes it easier for remote attackers to obtain administrative access by leveraging knowledge of this password.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
HP ArcSight Connectors | <=7.1.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2903 is considered critical due to its potential to allow unauthorized administrative access to systems.
To mitigate CVE-2015-2903, upgrade to HP ArcSight SmartConnectors version 7.1.6 or later.
CVE-2015-2903 is caused by a hardcoded password in the CWSAPI SOAP service of HP ArcSight SmartConnectors.
CVE-2015-2903 affects HP ArcSight SmartConnectors versions prior to 7.1.6.
Attackers can exploit CVE-2015-2903 to gain administrative access to systems running affected versions of HP ArcSight SmartConnectors.