Windows Event Log SmartConnector in HP ArcSight Connector Appliance before 6.1 uses world-writable permissions for exported report files, which allows local users to change or delete log data by modifying a file, a different vulnerability than CVE-2011-0770.
2011-07-19T21:55:00.790
2025-04-11T00:51:21.963
Deferred
CVSSv2: 3.6 (LOW)
AV:L/AC:L/Au:N/C:N/I:P/A:P
3.9
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | hp | windows_event_log_smartconnector | ≤ 6.0.0.60023.2 | Yes |
Hardware | hp | arcsight_c1000_appliance | * | Yes |
Hardware | hp | arcsight_c1300_appliance | * | Yes |
Hardware | hp | arcsight_c3200_appliance | * | Yes |
Hardware | hp | arcsight_c3400_appliance | * | Yes |
Hardware | hp | arcsight_c5200_appliance | * | Yes |
Hardware | hp | arcsight_c5400_appliance | * | Yes |