Remote Cross-Site Scripting in HPE LoadRunner and Performance Center
CVE-2017-8953
Key Information:
- Vendor
HP
- Vendor
- CVE Published:
- 15 February 2018
What is CVE-2017-8953?
A vulnerability exists in HPE LoadRunner and HPE Performance Center that allows an attacker to exploit Remote Cross-Site Scripting (XSS). This flaw permits attackers to inject malicious scripts into web applications accessed by users, potentially leading to unauthorized actions on behalf of the user. Affected versions include HPE LoadRunner v12.53 and earlier, and HPE Performance Center v12.53 and earlier. It is crucial for users to apply patches and follow best practices to mitigate risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
LoadRunner and Performance Center v12.53 and earlier, v12.53 and earlier
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved