PT-2016-5940 · Hewlett Packard · Hpe Ilo 4+2
Published
2016-11-18
·
Updated
2018-10-04
·
CVE-2016-4406
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
HPE iLO 3 versions prior to 1.88
HPE iLO 4 versions prior to 2.44
Description
A remote cross-site scripting issue was identified, which could be exploited to allow Cross-Site Scripting (XSS). This issue can be remotely exploited.
Recommendations
For HPE iLO 3 versions prior to 1.88, update to version 1.88 or later to resolve the issue.
For HPE iLO 4 versions prior to 2.44, update to version 2.44 or later to resolve the issue.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hpe Ilo
Hpe Ilo 3
Hpe Ilo 4