CVE-2016-1992: Infoleak
HPE ArcSight ESM before 6.8c, and ArcSight ESM Express before 6.9.1, allows remote authenticated users to obtain sensitive information via unspecified vectors.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1992?
CVE-2016-1992 is classified as a medium severity vulnerability that allows remote authenticated users to access sensitive information.
How do I fix CVE-2016-1992?
To remediate CVE-2016-1992, upgrade HPE ArcSight ESM to version 6.8c or later, or ArcSight ESM Express to version 6.9.1 or later.
Who is affected by CVE-2016-1992?
CVE-2016-1992 affects users of HPE ArcSight ESM versions prior to 6.8c and ArcSight ESM Express versions prior to 6.9.1.
What type of attack does CVE-2016-1992 enable?
CVE-2016-1992 enables remote authenticated users to exploit the vulnerability to gain access to sensitive information.
Is there a workaround for CVE-2016-1992?
There is no specific known workaround for CVE-2016-1992; updating to the latest versions is recommended.