CVE-2019-3480: XSS
Published Mar 25, 2019
·Updated
Mitigates a stored/reflected XSS issue in ArcSight Logger versions prior to 6.7.
Affected Software
1 affected component
HP ArcSight Logger<6.7
Event History
Mar 25, 2019
CVE Published
via MITRE·04:03 PM
Data Sourced
via MITRE·04:03 PM
DescriptionWeakness
Data Sourced
via NVD·05:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-3480?
CVE-2019-3480 has been classified as a medium severity vulnerability due to its potential for stored and reflected XSS attacks.
2
How do I fix CVE-2019-3480?
To remedy CVE-2019-3480, upgrade to ArcSight Logger version 6.7 or later.
3
What are the implications of CVE-2019-3480?
CVE-2019-3480 can allow attackers to execute arbitrary scripts in the context of affected users, leading to data theft or manipulation.
4
Which versions of ArcSight Logger are affected by CVE-2019-3480?
ArcSight Logger versions prior to 6.7 are vulnerable to CVE-2019-3480.
5
Is CVE-2019-3480 a widespread vulnerability?
CVE-2019-3480 primarily affects organizations using outdated versions of ArcSight Logger, particularly those below version 6.7.