First published: Wed Nov 04 2015(Updated: )
HP ArcSight Logger before 6.0 P2 does not limit attempts to authenticate to the SOAP interface, which makes it easier for remote attackers to obtain access via a brute-force approach.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenText ArcSight Logger | =6.0.0.7307.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-6029 is considered a medium severity vulnerability due to the potential for brute-force attacks on the SOAP interface.
To fix CVE-2015-6029, upgrade to HP ArcSight Logger version 6.0 P2 or later, which includes mitigations for this vulnerability.
CVE-2015-6029 poses the risk of unauthorized remote access through brute-force authentication attempts.
Yes, CVE-2015-6029 can be exploited over the internet if the SOAP interface is exposed and accessible.
CVE-2015-6029 affects the authentication mechanism of the SOAP interface within HP ArcSight Logger.