First published: Tue Apr 09 2019(Updated: )
A remote Cross-Site Scripting in HPE iLO 5 Web User Interface vulnerability was identified in HPE Integrated Lights-Out 5 (iLO 5) for Gen10 ProLiant Servers earlier than version v1.40.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
HPE Integrated Lights-Out 5 firmware | <1.40 | |
HPE ProLiant BL460c Gen10 Server Blade | ||
HP ProLiant DL120 Gen10 Server | ||
HP ProLiant DL160 Gen10 Server | ||
HP ProLiant DL180 Gen10 | ||
HP ProLiant DL20 Gen10 Server | ||
HPE ProLiant DL325 Gen10 Plus Server | ||
HP ProLiant DL360 Gen10 | ||
HPE ProLiant DL380 Gen10 Server | ||
HPE ProLiant DL385 Gen10 Plus Server | ||
HP ProLiant dl560 Gen10 | ||
HP ProLiant dl580 Gen10 | ||
HPE ProLiant Microserver Gen10 | ||
HP ProLiant ML110 Gen10 Server | ||
HPE ProLiant ML30 Gen10 | ||
HP ProLiant ML350 Gen10 Server | ||
HP ProLiant xl170r Gen10 | ||
HP ProLiant XL190r Gen10 Server | ||
HP ProLiant XL230k Gen10 Server | ||
HPE ProLiant XL450 Gen10 Server |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2018-7117.
The severity of CVE-2018-7117 is medium.
The affected software for CVE-2018-7117 is HPE Integrated Lights-Out 5 (iLO 5) for Gen10 ProLiant Servers earlier than version v1.40.
To fix CVE-2018-7117, you should update HPE Integrated Lights-Out 5 (iLO 5) to version v1.40 or later.
You can find more information about CVE-2018-7117 at the following links: [Link 1](https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03907en_us), [Link 2](https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03917en_us).