First published: Sun Dec 29 2013(Updated: )
Cross-site scripting (XSS) vulnerability in HP Service Manager WebTier and Windows Client 9.20 and 9.21 before 9.21.661 p8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: hp-security-alert@hp.com
Affected Software | Affected Version | How to fix |
---|---|---|
HP Service Manager | =9.20 | |
HP Service Manager | =9.21 | |
HP Service Manager | =9.20 | |
HP Service Manager | =9.21 | |
HP Service Manager | =9.20 | |
HP Service Manager | =9.21 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-6198 is classified as a critical vulnerability due to its potential for remote exploitation via cross-site scripting.
To fix CVE-2013-6198, upgrade to HP Service Manager and Web Client versions 9.21.661 p8 or later.
CVE-2013-6198 affects HP Service Manager versions 9.20 and 9.21 prior to 9.21.661 p8.
CVE-2013-6198 impacts both the HP Service Manager Web Tier and the Windows Client for versions 9.20 and 9.21.
Yes, CVE-2013-6198 allows remote attackers to inject arbitrary web script or HTML.