CVE-2018-6502: MFSBGN03824 rev.1 - ArcSight Management Center, Insufficient Access Control, Reflected Cross Site Scripting, Access Control vulnerability, Cross-Site Request Forgery (CSRF), Unauthenticated File Download, Directory Traversal Vulnerability
A potential Reflected Cross-Site Scripting (XSS) Security vulnerability has been identified in ArcSight Management Center (ArcMC) in all versions prior to 2.81. This vulnerability could be exploited to allow for Reflected Cross-site Scripting (XSS).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-6502?
CVE-2018-6502 is classified as a high severity vulnerability due to the potential for Reflected Cross-Site Scripting (XSS) attacks.
How do I fix CVE-2018-6502?
The vulnerability can be mitigated by upgrading ArcSight Management Center to version 2.81 or later.
What are the potential impacts of CVE-2018-6502?
Exploitation of CVE-2018-6502 may allow attackers to execute arbitrary JavaScript in the context of the user's browser.
Which versions of ArcSight Management Center are affected by CVE-2018-6502?
CVE-2018-6502 affects all versions of ArcSight Management Center prior to 2.81.
Is there a workaround for CVE-2018-6502?
There are no known workarounds for CVE-2018-6502, and upgrading to a secure version is recommended.