ArcSight Logger Security Vulnerability

buy Lyrica in ireland Overview :
‘External Task is undefined’ & ‘Syntax error’ errors appear on browser console after a Logger report query object is being created (new/modify) using IE browser.

Reports with lengthy names (> 60 characters) emailed via SMTP server are attached with an incorrect filename and extension.

Look At This Affected Product(s) :
  • ArcSight Logger 6.71
Vulnerability Details :
CVE ID : CVE-2019-11655 (unrestricted file upload)
Affected versions: Logger 6.7.0 and later​
Severity: Critical ​
CVSS 3.0 Rating: 9.9 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) ​
CWE Reference: 434 – Unrestricted Upload of File with Dangerous Typ​e
CVE ID : CVE-2019-11656 (stored XSS​)
Affected versions: versions prior to Logger 6.7.1 HotFix 6.7.1.8262.0​
Severity: Medium ​
CVSS 3.0 Rating: 5.4 (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N) ​
CWE Reference: 79 – Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)​

Remediation / Fixes :

Micro Focus recommends to apply this HotFix. HotFix 6.7.1.8262.0 on ArcSight Logger 6.7.1, either in software or appliance form factor. These fixes will also be part of the upcoming release of Logger.

Common Vulnerabilityies and Exposures

Contact us to get started

CVE-2024-22144 : ELI SCHEETZ ANTI-MALWARE SECURITY AND BRUTE-FORCE FIREWALL PLUGIN CODE INJECTION

CVE-2024-22144 : ELI SCHEETZ ANTI-MALWARE SECURITY AND BRUTE-FORCE FIREWALL PLUGIN CODE INJECTION

Description Improper Control of Generation of Code (‘Code Injection’) vulnerability in Eli Scheetz Anti-Malware Security and Brute-Force Firewall gotmls allows

CVE-2024-26922 : LINUX KERNEL UP TO 6.9-RC4 AMDGPU PRIVILEGE ESCALATION

CVE-2024-26922 : LINUX KERNEL UP TO 6.9-RC4 AMDGPU PRIVILEGE ESCALATION

Description In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: validate the parameters of bo mapping operations more

CVE-2024-21511 : MYSQL2 UP TO 3.9.6 READCODEFOR TIMEZONE CODE INJECTION

CVE-2024-21511 : MYSQL2 UP TO 3.9.6 READCODEFOR TIMEZONE CODE INJECTION

Description Versions of the package mysql2 before 3.9.7 are vulnerable to Arbitrary Code Injection due to improper sanitization of the