Release date:
Updated on:
Affected Systems:
Arcsight Connector Appliance 6.2.0.6244.0
Arcsight Logger Appliance 5.2.0.6288.0
Description:
--------------------------------------------------------------------------------
Bugtraq id: 54824
Cve id: CVE-2012-2960
HP Arcsight is a security software and compliance management solution company under HP.
The implementation of Arcsight applctor Appliance 6.2.0.6244.0 and Arcsight Logger Appliance 5.2.0.6288.0 has the HTML injection vulnerability, which can cause arbitrary script code to be executed in the browsers of affected sites, steal Cookie authentication creden。, or control the appearance of the site.
<* Source: Michael rutkoski
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Arcsight
--------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.arcsight.com/