6.9
CVSSv2

CVE-2015-2903

Published: 04/11/2015 Updated: 07/12/2016
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
VMScore: 614
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The CWSAPI SOAP service in HP ArcSight SmartConnectors prior to 7.1.6 has a hardcoded password, which makes it easier for remote malicious users to obtain administrative access by leveraging knowledge of this password.

Vulnerable Product Search on Vulmon Subscribe to Product

hp arcsight smartconnectors