CVE-2019-3481
HIGHHP ArcSight Logger < 6.7 - XML External Entity Injection
Title source: llmDescription
Mitigates a XML External Entity Parsing issue in ArcSight Logger versions prior to 6.7.
References (1)
Core 1
Core References
Various Sources x_refsource_misc
https://softwaresupport.softwaregrp.com/doc/KM03355866
Scores
CVSS v3
7.1
EPSS
0.0043
EPSS Percentile
62.8%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
Details
CWE
CWE-611
Status
published
Products (1)
hp/arcsight_logger
< 6.7
Published
Mar 25, 2019
Tracked Since
Feb 18, 2026