Lucene search

K
cveMicrofocusCVE-2020-9520
HistoryMar 25, 2020 - 9:15 p.m.

CVE-2020-9520

2020-03-2521:15:14
CWE-79
microfocus
web.nvd.nist.gov
54
cve-2020-9520
stored xss
micro focus vibe
security vulnerability
remote attack

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

AI Score

5.3

Confidence

High

EPSS

0.001

Percentile

29.2%

A stored XSS vulnerability was discovered in Micro Focus Vibe, affecting all Vibe version prior to 4.0.7. The vulnerability could allows a remote attacker to craft and store malicious content into Vibe such that when the content is viewed by another user of the system, attacker controlled JavaScript will execute in the security context of the target user’s browser.

Affected configurations

Nvd
Node
microfocusvibeRange<4.0.7
VendorProductVersionCPE
microfocusvibe*cpe:2.3:a:microfocus:vibe:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Micro Focus Vibe.",
    "vendor": "Micro Focus International",
    "versions": [
      {
        "status": "affected",
        "version": "All Vibe version prior to Vive 4.0.7."
      }
    ]
  }
]

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

AI Score

5.3

Confidence

High

EPSS

0.001

Percentile

29.2%

Related for CVE-2020-9520