PT-2017-17727 · Micro Focus · Micro Focus Enterprise Server+1
Published
2017-08-21
·
Updated
2019-10-09
·
CVE-2017-7422
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Micro Focus Enterprise Developer and Enterprise Server versions 2.3 through 2.3 Update 2 before Hotfix 9
Description
The issue concerns reflected and stored Cross-Site Scripting (XSS) vulnerabilities in the esfadmingui component. This allows remote authenticated attackers to bypass protection mechanisms and other security features if the component is configured. It is noted that esfadmingui is not enabled by default.
Recommendations
For Micro Focus Enterprise Developer and Enterprise Server versions 2.3 through 2.3 Update 2 before Hotfix 9, apply Hotfix 8 for version 2.3 Update 1 or Hotfix 9 for version 2.3 Update 2 to resolve the issue. As a temporary workaround, consider disabling the esfadmingui component until a patch is available.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Micro Focus Enterprise Developer
Micro Focus Enterprise Server