Lucene search

K
cveHpCVE-2014-7896
HistoryMar 03, 2015 - 11:59 a.m.

CVE-2014-7896

2015-03-0311:59:00
CWE-79
hp
web.nvd.nist.gov
20
cve-2014-7896
cross-site scripting
xss
vulnerabilities
hp xp p9000 command view
hp device manager
tiered storage manager
replication manager
global link manager
hp
web script
html
remote attackers

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6

Confidence

High

EPSS

0.064

Percentile

93.7%

Multiple cross-site scripting (XSS) vulnerabilities in HP XP P9000 Command View Advanced Edition Software Online Help, as used in HP Device Manager 6.x through 8.x before 8.1.2-00, HP XP P9000 Tiered Storage Manager 6.x through 8.x before 8.1.2-00, HP XP P9000 Replication Manager 6.x and 7.x before 7.6.1-06, and HP XP7 Global Link Manager Software (aka HGLM) 6.x through 8.x before 8.1.2-00, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Affected configurations

Nvd
Node
hpxp_p9000_device_managerRange8.1.1
OR
hpxp_p9000_replication_managerRange7.6.1
OR
hpxp_p9000_tiered_storage_managerRange8.1.1
OR
hpxp7_global_link_manager_softwareRange8.1.1
VendorProductVersionCPE
hpxp_p9000_device_manager*cpe:2.3:a:hp:xp_p9000_device_manager:*:*:*:*:*:*:*:*
hpxp_p9000_replication_manager*cpe:2.3:a:hp:xp_p9000_replication_manager:*:*:*:*:*:*:*:*
hpxp_p9000_tiered_storage_manager*cpe:2.3:a:hp:xp_p9000_tiered_storage_manager:*:*:*:*:*:*:*:*
hpxp7_global_link_manager_software*cpe:2.3:a:hp:xp7_global_link_manager_software:*:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6

Confidence

High

EPSS

0.064

Percentile

93.7%

Related for CVE-2014-7896