CVE-2016-2010: XSS
Cross-site scripting (XSS) vulnerability in HPE Network Node Manager i (NNMi) 9.20, 9.23, 9.24, 9.25, 10.00, and 10.01 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-2011.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2010?
CVE-2016-2010 is classified as a moderate severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2016-2010?
To fix CVE-2016-2010, update HPE Network Node Manager i to the latest version that is not affected by this vulnerability.
Who is affected by CVE-2016-2010?
CVE-2016-2010 affects remote authenticated users of HPE Network Node Manager i versions 9.20 through 10.01.
What types of attacks can be executed through CVE-2016-2010?
CVE-2016-2010 allows attackers to inject arbitrary web scripts or HTML, which could lead to data theft or session hijacking.
Is CVE-2016-2010 the same as CVE-2016-2011?
No, CVE-2016-2010 is a different vulnerability from CVE-2016-2011.