CVE-2020-11838

Cross Site Scripting (XSS) vulnerability in Micro Focus ArcSight Management Center product, Affecting versions 2.6.1, 2.7.x, 2.8.x, 2.9.x prior to 2.9.4. The vulnerabilities could be remotely exploited resulting in Cross-Site Scripting (XSS) or information disclosure.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:microfocus:arcsight_management_center:*:*:*:*:*:*:*:*
cpe:2.3:a:microfocus:arcsight_management_center:2.6.1:*:*:*:*:*:*:*

History

21 Nov 2024, 04:58

Type Values Removed Values Added
References () https://softwaresupport.softwaregrp.com/doc/KM03650893 - () https://softwaresupport.softwaregrp.com/doc/KM03650893 -

07 Nov 2023, 03:15

Type Values Removed Values Added
References (MISC) https://softwaresupport.softwaregrp.com/doc/KM03650893 - Vendor Advisory () https://softwaresupport.softwaregrp.com/doc/KM03650893 -

Information

Published : 2020-06-16 14:15

Updated : 2024-11-21 04:58


NVD link : CVE-2020-11838

Mitre link : CVE-2020-11838

CVE.ORG link : CVE-2020-11838


JSON object : View

Products Affected

microfocus

  • arcsight_management_center
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')