Cross-Site Scripting Vulnerability in Micro Focus Enterprise Developer and Server
CVE-2017-7422

5.4MEDIUM

What is CVE-2017-7422?

Reflected and stored Cross-Site Scripting (XSS) vulnerabilities exist in the esfadmingui component of Micro Focus Enterprise Developer and Enterprise Server versions 2.3, 2.3 Update 1 (prior to Hotfix 8), and 2.3 Update 2 (prior to Hotfix 9). These vulnerabilities enable remote authenticated attackers to exploit improper validation of user inputs, allowing them to bypass certain security mechanisms. Note that esfadmingui is not enabled by default, which may limit exposure unless explicitly configured.

Affected Version(s)

Micro Focus Enterprise Developer, Micro Focus Enterprise Server 2.3 before 2.3 Update 1, 2.3 Update 1 before Hotfix 8, 2.3 Update 2 before Hotfix 9

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.