CVE-2016-1991: High severity opentext arcsight enterprise security manager vulnerability
Published Mar 16, 2016
·Updated
HPE ArcSight ESM 5.x before 5.6, 6.0, 6.5.x before 6.5C SP1 Patch 2, and 6.8c before P1, and ArcSight ESM Express before 6.9.1, allows remote authenticated users to conduct unspecified "file download" attacks via unknown vectors.
Affected Software
5 affected components
MicroFocus Arcsight Enterprise Security Manager>=5.0<=5.6
MicroFocus Arcsight Enterprise Security Manager=6.0
MicroFocus Arcsight Enterprise Security Manager=6.5
MicroFocus Arcsight Enterprise Security Manager=6.8
MicroFocus Arcsight Enterprise Security Manager=6.9
Remediation
Event History
Mar 16, 2016
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-1991?
CVE-2016-1991 is classified as a medium severity vulnerability allowing certain file download attacks.
2
Who is affected by CVE-2016-1991?
CVE-2016-1991 affects multiple versions of HPE ArcSight ESM and ArcSight ESM Express products.
3
How do I fix CVE-2016-1991?
To fix CVE-2016-1991, update your HPE ArcSight ESM or ESM Express to the latest patched version.
4
What type of attack can CVE-2016-1991 enable?
CVE-2016-1991 can enable remote authenticated users to conduct unspecified file download attacks.
5
Is there a workaround for CVE-2016-1991?
Currently, there are no specific workarounds for CVE-2016-1991 other than applying the necessary software updates.