First published: Tue Sep 10 2019(Updated: )
HTTP cookie in Micro Focus Service manager, Versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. And Micro Focus Service Manager Chat Server, versions 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. And Micro Focus Service Manager Chat Service 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62.
Credit: security@microfocus.com
Affected Software | Affected Version | How to fix |
---|---|---|
HP Service Manager | =9.30 | |
HP Service Manager | =9.31 | |
HP Service Manager | =9.32 | |
HP Service Manager | =9.33 | |
HP Service Manager | =9.34 | |
HP Service Manager | =9.35 | |
HP Service Manager | =9.40 | |
HP Service Manager | =9.41 | |
HP Service Manager | =9.50 | |
HP Service Manager | =9.51 | |
HP Service Manager | =9.52 | |
HP Service Manager | =9.60 | |
HP Service Manager | =9.61 | |
HP Service Manager | =9.62 | |
Microfocus Service Manager Chat Service | =9.41 | |
Microfocus Service Manager Chat Service | =9.50 | |
Microfocus Service Manager Chat Service | =9.51 | |
Microfocus Service Manager Chat Service | =9.52 | |
Microfocus Service Manager Chat Service | =9.60 | |
Microfocus Service Manager Chat Service | =9.61 | |
Microfocus Service Manager Chat Service | =9.62 | |
Microfocus Service Manager Chat Server | =9.41 | |
Microfocus Service Manager Chat Server | =9.50 | |
Microfocus Service Manager Chat Server | =9.51 | |
Microfocus Service Manager Chat Server | =9.52 | |
Microfocus Service Manager Chat Server | =9.60 | |
Microfocus Service Manager Chat Server | =9.61 | |
Microfocus Service Manager Chat Server | =9.62 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11668 has a medium severity rating due to its potential impact on session management and user authentication.
To fix CVE-2019-11668, update your Micro Focus Service Manager and Chat Server/Service to the latest available versions as provided by the vendor.
CVE-2019-11668 affects Micro Focus Service Manager versions 9.30 to 9.62 and related Chat Server and Chat Service versions.
CVE-2019-11668 represents a vulnerability related to insecure HTTP cookie handling in the affected software.
There is no specific workaround for CVE-2019-11668; updating to the latest versions is recommended as the primary mitigation strategy.