Open Redirect Vulnerability in Micro Focus Network Automation
CVE-2021-38123

6.1MEDIUM

Key Information:

Vendor

Microfocus

Vendor
CVE Published:
7 September 2021

What is CVE-2021-38123?

An Open Redirect vulnerability exists in Micro Focus Network Automation, allowing attackers to redirect authenticated users to malicious external websites. This can have serious implications for user security and data integrity, potentially exposing sensitive information through crafted URLs. It is crucial for organizations using affected versions to apply patches and mitigate this risk promptly.

Affected Version(s)

Network Automation. Network Automation (NA) versions 10.4x, 10.5x, 2018.05, 2018.11, 2019.05, 2020.02, 2020.08, 2020.11, 2021.05.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.