CVE-2017-13989: High severity hp enterprise security manager vulnerability
An improper access control vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows unauthorized users to retrieve or modify storage information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-13989?
The severity of CVE-2017-13989 is classified as medium due to inadequate access controls allowing unauthorized access to sensitive data.
How do I fix CVE-2017-13989?
To fix CVE-2017-13989, upgrade to ArcSight ESM 6.9.1c Patch 4 or ArcSight ESM 6.11.0 Patch 1 or later.
Which versions of ArcSight are affected by CVE-2017-13989?
CVE-2017-13989 affects ArcSight ESM and ArcSight ESM Express versions prior to 6.9.1c Patch 4 and 6.11.0 Patch 1.
What type of vulnerability is CVE-2017-13989?
CVE-2017-13989 is an improper access control vulnerability that allows unauthorized users to retrieve or modify storage information.
Are there any known exploits for CVE-2017-13989?
As of now, there are no public exploits specifically targeting CVE-2017-13989.