CVE-2017-13986: HP Arcsight Enterprise Security Manager

Medium severity, CVSS 6.1. EPSS: 1% chance of exploitation in the next 30 days.

A reflected Cross-Site Scripting(XSS) vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows for unintended information when a specific URL is sent to the system.

Affected products

  • HP Arcsight Enterprise Security Manager: version 6.0 only; version 6.0c only; version 6.5 only; version 6.5c only; version 6.8 only; version 6.8c only; …
  • HP Arcsight Enterprise Security Manager Express: version 6.0 only; version 6.0c only; version 6.5 only; version 6.5c only; version 6.8 only; version 6.8c only; …

Published 2017-09-30. Last modified 2026-06-17.