Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Author

 Haiyan Song
LinkedIn
RSS
E-Mail

Profile of Haiyan Song

SVP Security Markets, Splunk
Member Since: 5/18/2016
Author
News & Commentary Posts: 1
Comments: 0

Haiyan leads the security business at Splunk and is responsible for driving Splunk's strategy and execution in the fast-growing security market. Splunk Inc. provides the leading software platform for real-time operational and security intelligence.

Previously, Haiyan spent over 8 years at ArcSight-HP Enterprise Security Products as vice president and general manager, where she was responsible for driving product strategies and business execution. During her time at ArcSight, she led and grew the product team through the company's IPO and subsequent acquisition by HP. Before joining ArcSight, Haiyan held various executive leadership positions at enterprise software companies and service providers including Escalate, Ketera Technology, Omniva Policy Systems and Sensage. She started her career at IBM Informix where she led the development of Informix-Online/Secure, its trusted relational database management system product and its system management portfolio.

Haiyan studied computer science at Tsinghua University in Beijing (CS 32, 1983), China. She holds a Bachelor of Science and Master of Science degree in Computer Engineering from Florida Atlantic University. Haiyan completed the Stanford Executive Program for General Management in 2012.

Articles by Haiyan Song
The Security of Cloud Applications
Hillel Solow, CTO and Co-founder, Protego,  7/11/2019
Where Businesses Waste Endpoint Security Budgets
Kelly Sheridan, Staff Editor, Dark Reading,  7/15/2019
US Mayors Commit to Just Saying No to Ransomware
Robert Lemos, Contributing Writer,  7/16/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Building and Managing an IT Security Operations Program
As cyber threats grow, many organizations are building security operations centers (SOCs) to improve their defenses. In this Tech Digest you will learn tips on how to get the most out of a SOC in your organization - and what to do if you can't afford to build one.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-13453
PUBLISHED: 2019-07-17
Zipios before 0.1.7 does not properly handle certain malformed zip archives and can go into an infinite loop, causing a denial of service. This is related to zipheadio.h:readUint32() and zipfile.cpp:Zipfile::Zipfile().
CVE-2019-4211
PUBLISHED: 2019-07-17
IBM QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 159131.
CVE-2019-4430
PUBLISHED: 2019-07-17
IBM Maximo Asset Management 7.6 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 162887.
CVE-2018-1921
PUBLISHED: 2019-07-17
IBM Campaign 9.1.0, 9.1.2, 10.1, and 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152857.
CVE-2018-2021
PUBLISHED: 2019-07-17
IBM QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 155345.