CVE-2017-14356: HP Arcsight Enterprise Security Manager

Critical severity, CVSS 9.8. EPSS: 1.8% chance of exploitation in the next 30 days.

An SQL Injection vulnerability in HP ArcSight ESM and HP ArcSight ESM Express, in any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1. This vulnerability could be exploited remotely to allow SQL injection.

Affected products

  • HP Arcsight Enterprise Security Manager: version 6.0 only; version 6.0c only; version 6.5 only; version 6.5c only; version 6.8 only; version 6.8c only; …
  • HP Arcsight Enterprise Security Manager Express: version 6.0 only; version 6.0c only; version 6.5 only; version 6.5c only; version 6.8 only; version 6.8c only; …

Published 2017-10-31. Last modified 2026-06-17.