CVE-2012-2018: XSS
Cross-site scripting (XSS) vulnerability in HP Network Node Manager i (NNMi) 8.x, 9.0x, and 9.1x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2018?
CVE-2012-2018 is classified as a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary web script or HTML.
How do I fix CVE-2012-2018?
To mitigate CVE-2012-2018, it is recommended to upgrade to a fixed version of HP Network Node Manager i that addresses this vulnerability.
Which versions of HP Network Node Manager i are affected by CVE-2012-2018?
CVE-2012-2018 affects HP Network Node Manager i versions 8.x, 9.0x, and 9.1x.
What kind of attacks can exploit CVE-2012-2018?
CVE-2012-2018 can be exploited by remote attackers to execute arbitrary web scripts or HTML in the context of the user's browser.
Is there a workaround for CVE-2012-2018?
While upgrading is the best solution, restricting access to the affected application may serve as a temporary workaround for CVE-2012-2018.