CVE-2017-7421
Summary
| CVE | CVE-2017-7421 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-08-21 15:29:00 UTC |
| Updated | 2023-11-07 02:50:00 UTC |
| Description | Reflected and stored Cross-Site Scripting (XSS, CWE-79) vulnerabilities in Directory Server (aka Enterprise Server Administration web UI) and ESMAC (aka Enterprise Server Monitor and Control) in Micro Focus Enterprise Developer and Enterprise Server 2.3 and earlier, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allow remote authenticated attackers to bypass protection mechanisms (CWE-693) and other security features. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microfocus | Directory Server | - | All | All | All |
| Application | Microfocus | Directory Server | - | All | All | All |
| Application | Microfocus | Enterprise Developer | 2.3 | All | All | All |
| Application | Microfocus | Enterprise Developer | 2.3 | update1 | All | All |
| Application | Microfocus | Enterprise Developer | 2.3 | update2 | All | All |
| Application | Microfocus | Enterprise Developer | 2.3 | All | All | All |
| Application | Microfocus | Enterprise Developer | 2.3 | update1 | All | All |
| Application | Microfocus | Enterprise Developer | 2.3 | update2 | All | All |
| Application | Microfocus | Enterprise Server | 2.3 | update1 | All | All |
| Application | Microfocus | Enterprise Server | 2.3 | update2 | All | All |
| Application | Microfocus | Enterprise Server | 2.3 | update1 | All | All |
| Application | Microfocus | Enterprise Server | 2.3 | update2 | All | All |
| Application | Microfocus | Enterprise Server | All | All | All | All |
| Application | Microfocus | Enterprise Server Monitor And Control | - | All | All | All |
| Application | Microfocus | Enterprise Server Monitor And Control | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Enterprise Server security fixes, July 2017 - Micro Focus Community - 1735728 | community.microfocus.com | ||
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.