Persistent Cross-Site Scripting, and non-persistent HTML Injection in HP Network Operations Management Ultimate, version 2017.07, 2017.11, 2018.02 and in Network Automation, version 10.00, 10.10, 10.11, 10.20, 10.30, 10.40, 10.50. This vulnerability could be remotely exploited to allow persistent cross-site scripting, and non-persistent HTML Injection.
References
Link | Resource |
---|---|
https://softwaresupport.softwaregrp.com/document/-/facetsearch/document/KM03158014 | Vendor Advisory |
http://www.securitytracker.com/id/1040900 | Third Party Advisory VDB Entry |
http://www.securityfocus.com/bid/104131 | Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Information
Published : 2018-05-22 12:29
Updated : 2019-10-09 16:41
NVD link : CVE-2018-6492
Mitre link : CVE-2018-6492
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
hp
- network_operations_management_ultimate
- network_automation