First published: Tue Mar 03 2015(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in HP XP P9000 Command View Advanced Edition Software Online Help, as used in HP Device Manager 6.x through 8.x before 8.1.2-00, HP XP P9000 Tiered Storage Manager 6.x through 8.x before 8.1.2-00, HP XP P9000 Replication Manager 6.x and 7.x before 7.6.1-06, and HP XP7 Global Link Manager Software (aka HGLM) 6.x through 8.x before 8.1.2-00, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: hp-security-alert@hp.com
Affected Software | Affected Version | How to fix |
---|---|---|
HP XP P9000 Device Manager | <=8.1.1 | |
HP XP7 Replication Manager | <=7.6.1 | |
HP XP7 Tiered Storage Manager | <=8.1.1 | |
Hitachi Global Link Manager | <=8.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2014-7896 is classified as medium due to its potential for exploitation via cross-site scripting (XSS).
To fix CVE-2014-7896, upgrade the affected HP software to version 8.1.2-00 or later for all impacted products.
CVE-2014-7896 affects HP XP P9000 Device Manager, Replication Manager, and Tiered Storage Manager versions prior to 8.1.2-00.
CVE-2014-7896 is classified as a cross-site scripting (XSS) vulnerability that could allow an attacker to execute scripts in a user's browser.
Yes, CVE-2014-7896 can potentially lead to data exposure by allowing attackers to execute malicious scripts in the context of the user's session.