First published: Wed Mar 16 2016(Updated: )
HPE ArcSight ESM 5.x before 5.6, 6.0, 6.5.x before 6.5C SP1 Patch 2, and 6.8c before P1, and ArcSight ESM Express before 6.9.1, allows remote authenticated users to conduct unspecified "file download" attacks via unknown vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenText ArcSight Enterprise Security Manager | >=5.0<=5.6 | |
OpenText ArcSight Enterprise Security Manager | =6.0 | |
OpenText ArcSight Enterprise Security Manager | =6.5 | |
OpenText ArcSight Enterprise Security Manager | =6.8 | |
OpenText ArcSight Enterprise Security Manager | =6.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1991 is classified as a medium severity vulnerability allowing certain file download attacks.
CVE-2016-1991 affects multiple versions of HPE ArcSight ESM and ArcSight ESM Express products.
To fix CVE-2016-1991, update your HPE ArcSight ESM or ESM Express to the latest patched version.
CVE-2016-1991 can enable remote authenticated users to conduct unspecified file download attacks.
Currently, there are no specific workarounds for CVE-2016-1991 other than applying the necessary software updates.