CVE-2018-6492
Persistent Cross-Site Scripting, and non-persistent HTML Injection in HP Network Operations Management Ultimate, version 2017.07, 2017.11, 2018.02 and in Network Automation, version 10.00, 10.10, 10.11, 10.20, 10.30, 10.40, 10.50.
Does this matter?
Lower severity and a low EPSS score (1.55%). Track it; it rarely justifies an emergency change on its own.
Description
Persistent Cross-Site Scripting, and non-persistent HTML Injection in HP Network Operations Management Ultimate, version 2017.07, 2017.11, 2018.02 and in Network Automation, version 10.00, 10.10, 10.11, 10.20, 10.30, 10.40, 10.50. This vulnerability could be remotely exploited to allow persistent cross-site scripting, and non-persistent HTML Injection.
- CVSS 3.0
- 6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 1.55% probability · 74th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- hp/network operations management ultimate · hp/network automation
- Source
- security@opentext.com
References
- http://www.securityfocus.com/bid/104131
- http://www.securitytracker.com/id/1040900
- https://softwaresupport.softwaregrp.com/document/-/facetsearch/document/KM03158014
- http://www.securityfocus.com/bid/104131
- http://www.securitytracker.com/id/1040900
- https://softwaresupport.softwaregrp.com/document/-/facetsearch/document/KM03158014
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.