CVE-2017-13988: HP Arcsight Enterprise Security Manager
Medium severity, CVSS 6.5. EPSS: 0.8% chance of exploitation in the next 30 days.
An improper access control vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows unauthorized users to alter the maximum size of storage groups and enable/disable the setting for the 'follow schedule' function.
Affected products
- HP Arcsight Enterprise Security Manager: version 6.0 only; version 6.0c only; version 6.5 only; version 6.5c only; version 6.8 only; version 6.8c only; …
- HP Arcsight Enterprise Security Manager Express: version 6.0 only; version 6.0c only; version 6.5 only; version 6.5c only; version 6.8 only; version 6.8c only; …
Published 2017-09-30. Last modified 2026-06-17.