CVE-2017-13991: HP Arcsight Enterprise Security Manager
Medium severity, CVSS 5.3. EPSS: 1.5% chance of exploitation in the next 30 days.
An information leakage vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows disclosure of product license features.
Affected products
- HP Arcsight Enterprise Security Manager: version 6.0 only; version 6.0c only; version 6.5 only; version 6.5c only; version 6.8 only; version 6.8c only; …
- HP Arcsight Enterprise Security Manager Express: version 6.0 only; version 6.0c only; version 6.5 only; version 6.5c only; version 6.8 only; version 6.8c only; …
Published 2017-09-30. Last modified 2026-06-17.