CVE-2018-6504: MFSBGN03824 rev.1 - ArcSight Management Center, Insufficient Access Control, Reflected Cross Site Scripting, Access Control vulnerability, Cross-Site Request Forgery (CSRF), Unauthenticated File Download, Directory Traversal Vulnerability
A potential Cross-Site Request Forgery (CSRF) vulnerability has been identified in ArcSight Management Center (ArcMC) in all versions prior to 2.81. This vulnerability could be exploited to allow for Cross-Site Request Forgery (CSRF).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-6504?
CVE-2018-6504 is a potential Cross-Site Request Forgery (CSRF) vulnerability identified in ArcSight Management Center (ArcMC) in all versions prior to 2.81.
How severe is CVE-2018-6504?
CVE-2018-6504 has a severity score of 8.8, which is considered high.
Which software versions are affected by CVE-2018-6504?
All versions of ArcSight Management Center (ArcMC) prior to 2.81 are affected by CVE-2018-6504.
What is Cross-Site Request Forgery (CSRF)?
Cross-Site Request Forgery (CSRF) is an attack that tricks the victim into submitting a malicious request.
How can I fix CVE-2018-6504?
To fix CVE-2018-6504, you should update ArcSight Management Center (ArcMC) to version 2.81 or later.