Cross-site Scripting Vulnerability in HPE 3PAR Service Processor
CVE-2019-5398
5.4MEDIUM
Summary
A remote cross-site scripting vulnerability exists in the HPE 3PAR Service Processor, which can be exploited by attackers to execute arbitrary scripts in the context of the user's session. This can lead to unauthorized actions being performed on behalf of the victim, compromising the security of the organization. Affected users should upgrade to version 5.0.5.1 or later to mitigate this risk.
Affected Version(s)
HPE 3PAR Service Processor prior to 5.0.5.1
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved