A remote code execution security vulnerability has been identified in all versions of the HP ArcSight WINC Connector prior to v7.3.0.
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Link | Tags |
---|---|
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c05313743 | vendor advisory |
http://www.securityfocus.com/bid/93789 | vdb entry third party advisory |
http://www.securitytracker.com/id/1037068 | vdb entry third party advisory |