SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-7421

Reflected and stored Cross-Site Scripting (XSS, CWE-79) vulnerabilities in Directory Server (aka Enterprise Server Administration web UI) and ESMAC (aka Enterprise Server Monitor and Control) in Micro Focus Enterprise Developer and Enterprise Server 2.3…

MEDIUM 6.1EPSS 1.26%

Does this matter?

Lower severity and a low EPSS score (1.26%). Track it; it rarely justifies an emergency change on its own.

Description

Reflected and stored Cross-Site Scripting (XSS, CWE-79) vulnerabilities in Directory Server (aka Enterprise Server Administration web UI) and ESMAC (aka Enterprise Server Monitor and Control) in Micro Focus Enterprise Developer and Enterprise Server 2.3 and earlier, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allow remote authenticated attackers to bypass protection mechanisms (CWE-693) and other security features.

CVSS 3.0
6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
1.26% probability · 68th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
microfocus/directory server · microfocus/enterprise developer · microfocus/enterprise server · microfocus/enterprise server monitor and control
Source
security@opentext.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.