Cross-Site Request Forgery Vulnerability in Micro Focus Enterprise Developer and Server
CVE-2017-7423
8.8HIGH
What is CVE-2017-7423?
A Cross-Site Request Forgery vulnerability exists in the esfadmingui component of Micro Focus Enterprise Developer and Enterprise Server, allowing unprivileged remote attackers to execute unauthorized actions. If the esfadmingui feature is enabled, attackers can forge requests that lead to the creation of new privileged credentials, resulting in privilege elevation. This vulnerability affects specific versions of the software, posing significant risks if left unaddressed.
Affected Version(s)
Micro Focus Enterprise Developer, Micro Focus Enterprise Server 2.3 before 2.3 Update 1, 2.3 Update 1 before Hotfix 8, 2.3 Update 2 before Hotfix 9