CVE-2017-14356: HP Arcsight Enterprise Security Manager
Critical severity, CVSS 9.8. EPSS: 1.8% chance of exploitation in the next 30 days.
An SQL Injection vulnerability in HP ArcSight ESM and HP ArcSight ESM Express, in any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1. This vulnerability could be exploited remotely to allow SQL injection.
Affected products
- HP Arcsight Enterprise Security Manager: version 6.0 only; version 6.0c only; version 6.5 only; version 6.5c only; version 6.8 only; version 6.8c only; …
- HP Arcsight Enterprise Security Manager Express: version 6.0 only; version 6.0c only; version 6.5 only; version 6.5c only; version 6.8 only; version 6.8c only; …
Published 2017-10-31. Last modified 2026-06-17.