CVE-2016-1991

HPE ArcSight ESM 5.x before 5.6, 6.0, 6.5.x before 6.5C SP1 Patch 2, and 6.8c before P1, and ArcSight ESM Express before 6.9.1, allows remote authenticated users to conduct unspecified "file download" attacks via unknown vectors.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8 HIGH
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 66%
VendorProductVersion
microfocusarcsight_enterprise_security_manager
5.0 ≤
𝑥
≤ 5.6
microfocusarcsight_enterprise_security_manager
6.0
microfocusarcsight_enterprise_security_manager
6.5
microfocusarcsight_enterprise_security_manager
6.8
microfocusarcsight_enterprise_security_manager
6.9
𝑥
= Vulnerable software versions