Cross-Site Scripting Vulnerability in Micro Focus Enterprise Developer and Server
CVE-2017-7422
What is CVE-2017-7422?
Reflected and stored Cross-Site Scripting (XSS) vulnerabilities exist in the esfadmingui component of Micro Focus Enterprise Developer and Enterprise Server versions 2.3, 2.3 Update 1 (prior to Hotfix 8), and 2.3 Update 2 (prior to Hotfix 9). These vulnerabilities enable remote authenticated attackers to exploit improper validation of user inputs, allowing them to bypass certain security mechanisms. Note that esfadmingui is not enabled by default, which may limit exposure unless explicitly configured.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Micro Focus Enterprise Developer, Micro Focus Enterprise Server 2.3 before 2.3 Update 1, 2.3 Update 1 before Hotfix 8, 2.3 Update 2 before Hotfix 9
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
