Cross Site Scripting Vulnerability in HPE Superdome Flex Servers
CVE-2021-26589
6.1MEDIUM
What is CVE-2021-26589?
A security vulnerability in HPE Superdome Flex Servers has been identified that could be exploited remotely through Cross Site Scripting (XSS). The root cause is related to the Session Cookie lacking an HttpOnly Attribute, which potentially exposes sensitive data to attackers. HPE has issued a firmware update to address and mitigate this issue, improving the overall security posture of the affected servers.
Affected Version(s)
HPE Superdome Flex Server Prior to Version 3.40.106