First published: Tue Apr 09 2019(Updated: )
A remote Cross-Site Scripting in HPE iLO 5 Web User Interface vulnerability was identified in HPE Integrated Lights-Out 5 (iLO 5) for Gen10 ProLiant Servers earlier than version v1.40.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hp Integrated Lights-out 5 Firmware | <1.40 | |
Hp Proliant Bl460c Gen10 | ||
Hp Proliant Dl120 Gen10 | ||
Hp Proliant Dl160 Gen10 | ||
Hp Proliant Dl180 Gen10 | ||
Hp Proliant Dl20 Gen10 | ||
Hp Proliant Dl325 Gen10 | ||
Hp Proliant Dl360 Gen10 | ||
Hp Proliant Dl380 Gen10 | ||
Hp Proliant Dl385 Gen10 | ||
Hp Proliant Dl560 Gen10 | ||
Hp Proliant Dl580 Gen10 | ||
Hp Proliant Microserver Gen10 | ||
Hp Proliant Ml110 Gen10 | ||
Hp Proliant Ml30 Gen10 | ||
Hp Proliant Ml350 Gen10 | ||
Hp Proliant Xl170r Gen10 | ||
Hp Proliant Xl190r Gen10 | ||
Hp Proliant Xl230k Gen10 | ||
Hp Proliant Xl450 Gen10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2018-7117.
The severity of CVE-2018-7117 is medium.
The affected software for CVE-2018-7117 is HPE Integrated Lights-Out 5 (iLO 5) for Gen10 ProLiant Servers earlier than version v1.40.
To fix CVE-2018-7117, you should update HPE Integrated Lights-Out 5 (iLO 5) to version v1.40 or later.
You can find more information about CVE-2018-7117 at the following links: [Link 1](https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03907en_us), [Link 2](https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03917en_us).