CVE-2015-6864: Input Validation
Published Jan 16, 2016
·Updated
HPE ArcSight Logger before 6.1P1 allows remote authenticated users to execute arbitrary code via unspecified input to the (1) Intellicus or (2) client-certificate upload component.
Affected Software
1 affected component
HP ArcSight Logger<=6.1
Remediation
Event History
Jan 16, 2016
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-6864?
CVE-2015-6864 has a high severity rating due to its ability to allow remote authenticated users to execute arbitrary code.
2
How do I fix CVE-2015-6864?
To fix CVE-2015-6864, upgrade HPE ArcSight Logger to version 6.1P1 or later.
3
Who is affected by CVE-2015-6864?
CVE-2015-6864 affects users of HPE ArcSight Logger versions prior to 6.1P1.
4
What types of input are involved in CVE-2015-6864?
CVE-2015-6864 involves unspecified input to the Intellicus or client-certificate upload components.
5
What mitigation strategies are available for CVE-2015-6864?
Mitigation strategies for CVE-2015-6864 include applying patches and limiting remote authenticated user access.