Multiple HP Products CVE-2014-7896 Multiple Cross Site Scripting Vulnerabilities
BID:72847
Info
Multiple HP Products CVE-2014-7896 Multiple Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 72847 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-7896 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 02 2015 12:00AM |
| Updated: | Mar 02 2015 12:00AM |
| Credit: | HP |
| Vulnerable: |
HP XP7 Global Link Manager Software 8.0.0-00 HP XP7 Global Link Manager Software 7.6.0-02 HP XP7 Global Link Manager Software 6.4.0-00 HP XP P9000 Tiered Storage Manager 6.0 HP XP P9000 Tiered Storage Manager 8.0.0-06 HP XP P9000 Tiered Storage Manager 8.0.0-00 HP XP P9000 Tiered Storage Manager 7.6.1-06 HP XP P9000 Replication Manager 6.0.0-00 HP Device Manager 6.0 HP Device Manager 8.0.0-06 HP Device Manager 8.0.0-00 HP Device Manager 7.6.1-06 |
| Not Vulnerable: |
HP XP7 Global Link Manager Software 8.1.2 HP XP P9000 Tiered Storage Manager 8.1.2 HP XP P9000 Replication Manager 7.6.1-06 HP Device Manager 8.1.2 |
Discussion
Multiple HP Products CVE-2014-7896 Multiple Cross Site Scripting Vulnerabilities
Multiple HP products are prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
The following products are affected:
HP Device Manager 6.0.0 versions prior to 8.1.2 are affected.
HP XP P9000 Tiered Storage Manager 6.0.0 versions prior to 8.1.2 are affected.
HP XP P9000 Replication Manager 6.0.0 versions prior to 7.6.1-06 are affected.
HP XP7 Global Link Manager Software 6.4.0 versions prior to 8.1.2 are affected.
Multiple HP products are prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
The following products are affected:
HP Device Manager 6.0.0 versions prior to 8.1.2 are affected.
HP XP P9000 Tiered Storage Manager 6.0.0 versions prior to 8.1.2 are affected.
HP XP P9000 Replication Manager 6.0.0 versions prior to 7.6.1-06 are affected.
HP XP7 Global Link Manager Software 6.4.0 versions prior to 8.1.2 are affected.
Solution / Fix
Multiple HP Products CVE-2014-7896 Multiple Cross Site Scripting Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.