HP ArcSight Logger before 6.0 P2 does not limit attempts to authenticate to the SOAP interface, which makes it easier for remote attackers to obtain access via a brute-force approach.
Software security is not security software. Here we're concerned with topics like authentication, access control, confidentiality, cryptography, and privilege management.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/77128 | vdb entry |
https://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c04863612 | vendor advisory |
http://www.kb.cert.org/vuls/id/842252 | third party advisory us government resource |