CVE-2015-2903: Medium severity hp arcsight connectors vulnerability
Published Nov 4, 2015
·Updated
The CWSAPI SOAP service in HP ArcSight SmartConnectors before 7.1.6 has a hardcoded password, which makes it easier for remote attackers to obtain administrative access by leveraging knowledge of this password.
Affected Software
1 affected component
HP ArcSight SmartConnectors<=7.1.5
Event History
Nov 4, 2015
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-2903?
CVE-2015-2903 is considered critical due to its potential to allow unauthorized administrative access to systems.
2
How do I fix CVE-2015-2903?
To mitigate CVE-2015-2903, upgrade to HP ArcSight SmartConnectors version 7.1.6 or later.
3
What causes CVE-2015-2903?
CVE-2015-2903 is caused by a hardcoded password in the CWSAPI SOAP service of HP ArcSight SmartConnectors.
4
Who is affected by CVE-2015-2903?
CVE-2015-2903 affects HP ArcSight SmartConnectors versions prior to 7.1.6.
5
What can attackers do with CVE-2015-2903?
Attackers can exploit CVE-2015-2903 to gain administrative access to systems running affected versions of HP ArcSight SmartConnectors.