A remote cross-site scripting vulnerability in HP UCMDB Foundation Software versions 10.10, 10.11, 10.20, 10.21, 10.22, 10.30, 10.31, 10.32, and 10.33 could be remotely exploited to allow cross-site scripting.
References
Link | Resource |
---|---|
https://www.auscert.org.au/bulletins/53150 | Third Party Advisory |
https://softwaresupport.hpe.com/km/KM02977984 | Permissions Required Vendor Advisory |
http://www.securityfocus.com/bid/101254 | |
https://www.tenable.com/security/research/tra-2017-32 |
Configurations
Configuration 1 (hide)
|
Information
Published : 2017-10-05 08:29
Updated : 2017-11-10 18:29
NVD link : CVE-2017-14354
Mitre link : CVE-2017-14354
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
hp
- ucmdb_foundation_software