CVE-2016-2011: XSS
Cross-site scripting (XSS) vulnerability in HPE Network Node Manager i (NNMi) 9.20, 9.23, 9.24, 9.25, 10.00, and 10.01 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-2010.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2011?
CVE-2016-2011 is classified as a medium severity vulnerability due to the risk of cross-site scripting (XSS).
How do I fix CVE-2016-2011?
To fix CVE-2016-2011, update HPE Network Node Manager i to a version that is not vulnerable, specifically those released after the affected versions listed.
Who is impacted by CVE-2016-2011?
Remote authenticated users of HPE Network Node Manager i versions 9.20 to 10.01 are impacted by CVE-2016-2011.
What types of attacks can occur due to CVE-2016-2011?
CVE-2016-2011 could allow attackers to inject arbitrary web scripts or HTML, leading to data theft or session hijacking.
Is CVE-2016-2011 a known issue in other software products?
CVE-2016-2011 is specific to HPE Network Node Manager i and is not reported as a known issue in other software products.