Software
Vulnerabilities Found in HP ArcSight Products
Reported by securityweek.com
HP has started releasing software updates for its ArcSight enterprise security management solution to address a series of vulnerabilities reported by researchers.
An advisory published by CERT on Monday shows that ArcSight Logger, a log management software tool, is plagued by an authentication bypass vulnerability (CVE-2015-2136) that allows a remote, authenticated user without Logger Search permissions to conduct searches through the SOAP interface.