First published: Wed Nov 16 2011(Updated: )
Cross-site scripting (XSS) vulnerability in HP Network Node Manager i (NNMi) 9.0x and 9.1x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2011-4155.
Credit: hp-security-alert@hp.com
Affected Software | Affected Version | How to fix |
---|---|---|
HP Network Node Manager i | =9.03 | |
HP Network Node Manager i | =9.10 | |
HP Network Node Manager i | =9.01 | |
HP Network Node Manager i | =9.02 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-4156 is classified as a medium severity vulnerability due to its potential for exploitation through cross-site scripting.
To fix CVE-2011-4156, upgrade to a patched version of HP Network Node Manager i that mitigates the cross-site scripting vulnerability.
CVE-2011-4156 affects HP Network Node Manager i versions 9.01, 9.02, 9.03, 9.10, and 9.11.
Yes, CVE-2011-4156 allows remote attackers to inject arbitrary web scripts which can be exploited over the web.
CVE-2011-4156 can be leveraged for attacks such as session hijacking, phishing, and distribution of malware via cross-site scripting.