CVE-2016-1991

EUVD-2016-3080
HPE ArcSight ESM 5.x before 5.6, 6.0, 6.5.x before 6.5C SP1 Patch 2, and 6.8c before P1, and ArcSight ESM Express before 6.9.1, allows remote authenticated users to conduct unspecified "file download" attacks via unknown vectors.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8 HIGH
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 64%
Affected Products (NVD)
VendorProductVersion
microfocusarcsight_enterprise_security_manager
5.0 ≤
𝑥
≤ 5.6
microfocusarcsight_enterprise_security_manager
6.0
microfocusarcsight_enterprise_security_manager
6.5
microfocusarcsight_enterprise_security_manager
6.8
microfocusarcsight_enterprise_security_manager
6.9
𝑥
= Vulnerable software versions