CVE-2016-4380: XSS
Published Sep 8, 2016
·Updated
Cross-site scripting (XSS) vulnerability in the AdminUI in HPE Operations Manager 9.21.x before 9.21.130 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
3 affected components
HP Operations Manager Linux<=9.21
HP Operations Manager Solaris<=9.21
HP Operations Manager Unix<=9.21
Remediation
Event History
Sep 8, 2016
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-4380?
CVE-2016-4380 is considered a high severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2016-4380?
To mitigate CVE-2016-4380, update HPE Operations Manager to version 9.21.130 or later.
3
Who is affected by CVE-2016-4380?
CVE-2016-4380 affects remote authenticated users of HPE Operations Manager versions prior to 9.21.130.
4
What types of exploits are possible with CVE-2016-4380?
Exploitation of CVE-2016-4380 may allow attackers to inject arbitrary web scripts or HTML into the AdminUI.
5
In which systems can CVE-2016-4380 be found?
CVE-2016-4380 is found in HPE Operations Manager on Linux, Solaris, and Unix systems up to version 9.21.