First published: Mon Mar 29 2010(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in HP Project and Portfolio Management Center (PPMC, formerly Mercury IT Governance) 7.1 through SP10 and 7.5 through SP3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: hp-security-alert@hp.com
Affected Software | Affected Version | How to fix |
---|---|---|
HP Project and Portfolio Management Center | <=7.1 | |
HP Project and Portfolio Management Center | <=7.5 | |
HPE HP-UX | =b.11.23 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-0452 identifies multiple cross-site scripting vulnerabilities in HP Project and Portfolio Management Center versions 7.1 through SP10 and 7.5 through SP3.
The impact of CVE-2010-0452 allows remote attackers to inject arbitrary web script or HTML into the affected systems.
To identify if your system is affected by CVE-2010-0452, check if you are running HP Project and Portfolio Management Center versions 7.1 through SP10 or 7.5 through SP3.
To protect against CVE-2010-0452, it's recommended to upgrade to a patched version or apply security updates provided by HP that address these vulnerabilities.
Anyone with remote access to the affected HP Project and Portfolio Management Center software can exploit the vulnerabilities identified in CVE-2010-0452.