HP Operations Manager CVE-2014-2647 Multiple Unspecified Cross Site Scripting Vulnerabilities
BID:70607
Info
HP Operations Manager CVE-2014-2647 Multiple Unspecified Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 70607 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-2647 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 15 2014 12:00AM |
| Updated: | Oct 15 2014 12:00AM |
| Credit: | The vendor reported these issues. |
| Vulnerable: |
HP Operations Manager 0 HP Operations Agent 8.60.7 HP Operations Agent 8.60.501 HP Operations Agent 8.60.5 HP Operations Agent 8.60.008 HP Operations Agent 8.60.007 HP Operations Agent 8.60.006 HP Operations Agent 8.60.005 HP Operations Agent 8.60 HP Operations Agent 8.53 HP Operations Agent 8.52 HP Operations Agent 8.51.102 HP Operations Agent 8.51 HP Operations Agent 7.36 HP Operations Agent 11.03.12 HP Operations Agent 11.03 HP Operations Agent 11.01 HP Operations Agent 11.0 |
| Not Vulnerable: |
HP Operations Agent 11.14 |
Discussion
HP Operations Manager CVE-2014-2647 Multiple Unspecified Cross Site Scripting Vulnerabilities
HP Operations Manager is prone to multiple unspecified cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
HP Operations Manager is prone to multiple unspecified cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Exploit / POC
HP Operations Manager CVE-2014-2647 Multiple Unspecified Cross Site Scripting Vulnerabilities
Attackers can exploit these issues by enticing an unsuspecting user to follow a malicious URI.
Attackers can exploit these issues by enticing an unsuspecting user to follow a malicious URI.
Solution / Fix
HP Operations Manager CVE-2014-2647 Multiple Unspecified Cross Site Scripting Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.