CVE-2017-13988: Medium severity hp enterprise security manager vulnerability
An improper access control vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows unauthorized users to alter the maximum size of storage groups and enable/disable the setting for the 'follow schedule' function.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-13988?
CVE-2017-13988 has a medium severity level due to its potential for unauthorized users to change critical system settings.
How do I fix CVE-2017-13988?
To fix CVE-2017-13988, upgrade to an ArcSight ESM version that is 6.9.1c Patch 4 or higher, or 6.11.0 Patch 1.
Which software versions are affected by CVE-2017-13988?
CVE-2017-13988 affects all versions of ArcSight ESM and ArcSight ESM Express prior to 6.9.1c Patch 4 and 6.11.0 Patch 1.
What can unauthorized users do due to CVE-2017-13988?
Unauthorized users can alter the maximum size of storage groups and enable or disable the 'follow schedule' function.
Is CVE-2017-13988 present in ArcSight ESM 6.9.1c?
No, CVE-2017-13988 is not present in ArcSight ESM 6.9.1c Patch 4 or higher.