First published: Fri Nov 08 2024(Updated: )
A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in OpenText ArcSight Management Center and ArcSight Platform. The vulnerability could be remotely exploited.
Credit: security@opentext.com
Affected Software | Affected Version | How to fix |
---|---|---|
OpenText ArcSight Management Center | <3.2.5 | |
OpenText ArcSight Management Center | =3.2.5 | |
Micro Focus ArcSight Platform | <24.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-9841 is classified as a high severity Reflected Cross-Site Scripting (XSS) vulnerability.
To fix CVE-2024-9841, upgrade to the latest version of OpenText ArcSight Management Center or ArcSight Platform that addresses the vulnerability.
CVE-2024-9841 affects OpenText ArcSight Management Center versions prior to 3.2.5 and ArcSight Platform versions prior to 24.2.2.
Yes, CVE-2024-9841 can be remotely exploited, allowing attackers to execute scripts in the context of the user's browser.
CVE-2024-9841 could allow an attacker to perform actions on behalf of the user or steal sensitive information through a maliciously crafted request.