CVE-2010-3985: XSS
Published Oct 26, 2010
·Updated
Cross-site scripting (XSS) vulnerability in HP Operations Orchestration before 9.0, when Internet Explorer 6.0 is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
4 affected components
HP Operations Orchestration<=7.5
HP Operations Orchestration=7.1
HP Operations Orchestration=7.2
Microsoft Internet Explorer=6.0
Event History
Oct 26, 2010
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
07:00 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What versions of HP Operations Orchestration are affected by CVE-2010-3985?
CVE-2010-3985 affects HP Operations Orchestration versions prior to 9.0, including 7.1, 7.2, and up to 7.5.
2
What type of vulnerability is CVE-2010-3985?
CVE-2010-3985 is a cross-site scripting (XSS) vulnerability.
3
How can I mitigate the risk of CVE-2010-3985?
To mitigate CVE-2010-3985, upgrade to HP Operations Orchestration version 9.0 or later.
4
Is Internet Explorer 6.0 a requirement for CVE-2010-3985 to be exploited?
Yes, CVE-2010-3985 specifically details that Internet Explorer 6.0 is needed for the vulnerability to be exploited.
5
What are the implications of CVE-2010-3985?
The implications of CVE-2010-3985 include the potential for remote attackers to inject arbitrary web scripts or HTML.