CVE-2014-2644: XSS
Published Oct 6, 2014
·Updated
Cross-site scripting (XSS) vulnerability in HP Systems Insight Manager (SIM) before 7.4 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
Affected Software
4 affected components
HP Systems Insight Manager<=7.3
HP Systems Insight Manager=7.0
HP Systems Insight Manager=7.1
HP Systems Insight Manager=7.2
Event History
Oct 6, 2014
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-2644?
CVE-2014-2644 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2014-2644?
To mitigate CVE-2014-2644, upgrade HP Systems Insight Manager to version 7.4 or later.
3
What kind of attack can be executed through CVE-2014-2644?
CVE-2014-2644 allows remote attackers to perform cross-site scripting (XSS) attacks, injecting arbitrary web scripts or HTML.
4
Which versions of HP Systems Insight Manager are affected by CVE-2014-2644?
CVE-2014-2644 affects HP Systems Insight Manager versions 7.0 to 7.3 inclusive.
5
Is CVE-2014-2644 exploit related to specific vectors?
The exact vectors for exploitation of CVE-2014-2644 are currently unknown, allowing for arbitrary code injection.