PT-2017-17727 · Micro Focus · Micro Focus Enterprise Server+1

Publicado

2017-08-21

·

Atualizado

2019-10-09

·

CVE-2017-7422

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Micro Focus Enterprise Developer and Enterprise Server versions 2.3 through 2.3 Update 2 before Hotfix 9
Description The issue concerns reflected and stored Cross-Site Scripting (XSS) vulnerabilities in the esfadmingui component. This allows remote authenticated attackers to bypass protection mechanisms and other security features if the component is configured. It is noted that esfadmingui is not enabled by default.
Recommendations For Micro Focus Enterprise Developer and Enterprise Server versions 2.3 through 2.3 Update 2 before Hotfix 9, apply Hotfix 8 for version 2.3 Update 1 or Hotfix 9 for version 2.3 Update 2 to resolve the issue. As a temporary workaround, consider disabling the esfadmingui component until a patch is available.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-7422

Produtos afetados

Micro Focus Enterprise Developer
Micro Focus Enterprise Server