Reflected XSS Vulnerability in Micro Focus Solutions Business Manager Application Repository
CVE-2019-18944

4.9MEDIUM

Key Information:

Vendor
CVE Published:
26 February 2021

What is CVE-2019-18944?

Micro Focus Solutions Business Manager Application Repository versions before 11.7.1 exhibit a reflected cross-site scripting vulnerability, which could be exploited by attackers to inject malicious scripts into the web application. This could lead to unauthorized actions performed on behalf of the user, compromising the security of sensitive information and potentially enabling further attacks.

Affected Version(s)

Solutions Business Manager < 11.7.1

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Special thanks goes to Alessio Sergi of Verizon Enterprise Solutions for responsibly disclosing this CVE.
.