CVE-2014-7896: XSS
Multiple cross-site scripting (XSS) vulnerabilities in HP XP P9000 Command View Advanced Edition Software Online Help, as used in HP Device Manager 6.x through 8.x before 8.1.2-00, HP XP P9000 Tiered Storage Manager 6.x through 8.x before 8.1.2-00, HP XP P9000 Replication Manager 6.x and 7.x before 7.6.1-06, and HP XP7 Global Link Manager Software (aka HGLM) 6.x through 8.x before 8.1.2-00, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-7896?
The severity of CVE-2014-7896 is classified as medium due to its potential for exploitation via cross-site scripting (XSS).
How do I fix CVE-2014-7896?
To fix CVE-2014-7896, upgrade the affected HP software to version 8.1.2-00 or later for all impacted products.
Which HP products are affected by CVE-2014-7896?
CVE-2014-7896 affects HP XP P9000 Device Manager, Replication Manager, and Tiered Storage Manager versions prior to 8.1.2-00.
What type of vulnerability is CVE-2014-7896?
CVE-2014-7896 is classified as a cross-site scripting (XSS) vulnerability that could allow an attacker to execute scripts in a user's browser.
Can CVE-2014-7896 lead to data exposure?
Yes, CVE-2014-7896 can potentially lead to data exposure by allowing attackers to execute malicious scripts in the context of the user's session.