CVE-2015-6863: Input Validation
Published Jan 16, 2016
·Updated
HPE ArcSight Logger before 6.1P1 allows remote attackers to execute arbitrary code via unspecified input to the (1) Intellicus or (2) client-certificate upload component.
Affected Software
1 affected component
HP ArcSight Logger<=6.1
Remediation
Event History
Jan 16, 2016
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-6863?
CVE-2015-6863 has been classified with high severity due to its potential to allow remote code execution.
2
How do I fix CVE-2015-6863?
To fix CVE-2015-6863, upgrade HPE ArcSight Logger to version 6.1P1 or later.
3
What are the potential impacts of CVE-2015-6863?
The potential impacts of CVE-2015-6863 include unauthorized remote code execution, which can compromise system integrity.
4
Which versions of HPE ArcSight Logger are affected by CVE-2015-6863?
HPE ArcSight Logger versions before 6.1P1 are affected by CVE-2015-6863.
5
Who can exploit CVE-2015-6863?
Remote attackers with access to the vulnerable components can exploit CVE-2015-6863 to execute arbitrary code.