Overview
HP ArcSight Logger contains multiple vulnerabilities, allowing authentication bypass and privilege escalation in certain scenarios.
Description
| CWE-285: Improper Authorization - CVE-2015-2136 A remote authenticated user without Logger Search permissions may be able to bypass authorization and perform searches via the SOAP interface. | 
Impact
| An authenticated remote user without ArcSight Logger search privileges may be able to perform Logger searches. An unauthenticated remote user may be able to brute force guess a password without triggering any alerts. A user with arcsight credentials may be able to execute commands with the privileges of root. | 
Solution
| Apply an update | 
| Restrict access to the system and network | 
Vendor Information
CVSS Metrics
| Group | Score | Vector | 
|---|---|---|
| Base | 4 | AV:N/AC:L/Au:S/C:P/I:N/A:N | 
| Temporal | 3.1 | E:POC/RL:OF/RC:C | 
| Environmental | 2.3 | CDP:ND/TD:M/CR:ND/IR:ND/AR:ND | 
References
- https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04762372
- https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay/?docId=emr_na-c04863612
- http://cwe.mitre.org/data/definitions/285.html
- http://cwe.mitre.org/data/definitions/307.html
- http://cwe.mitre.org/data/definitions/653.html
Acknowledgements
Thanks to Hubert Mach and Julian Horoszkiewicz for reporting these issues to us.
This document was written by Garret Wassermann.
Other Information
| CVE IDs: | CVE-2015-2136, CVE-2015-6029, CVE-2015-6030 | 
| Date Public: | 2015-10-19 | 
| Date First Published: | 2015-10-19 | 
| Date Last Updated: | 2015-10-26 05:00 UTC | 
| Document Revision: | 53 |