First published: Wed Jun 05 2019(Updated: )
A remote cross site scripting vulnerability was identified in HPE Integrated Lights-Out 4 (iLO 4) earlier than v2.61b for Gen9 servers and Integrated Lights-Out 5 (iLO 5) for Gen10 Servers earlier than version v1.39.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hp Integrated Lights-out 5 Firmware | <=1.39 | |
Hp Proliant Bl460c Gen10 | ||
Hp Proliant Dl120 Gen10 | ||
Hp Proliant Dl160 Gen10 | ||
Hp Proliant Dl180 Gen10 | ||
Hp Proliant Dl20 Gen10 | ||
Hp Proliant Dl325 Gen10 | ||
Hp Proliant Dl360 Gen10 | ||
Hp Proliant Dl380 Gen10 | ||
Hp Proliant Dl385 Gen10 | ||
Hp Proliant Dl560 Gen10 | ||
Hp Proliant Dl580 Gen10 | ||
Hp Proliant Microserver Gen10 | ||
Hp Proliant Ml110 Gen10 | ||
Hp Proliant Ml350 Gen10 | ||
Hp Proliant Xl170r Gen10 | ||
Hp Proliant Xl190r Gen10 | ||
Hp Proliant Xl230k Gen10 | ||
Hp Proliant Xl450 Gen10 | ||
Hp Integrated Lights-out 4 Firmware | <=2.61b | |
Hp Proliant Bl460c Gen9 | ||
Hp Proliant Dl120 Gen9 | ||
Hp Proliant Dl180 Gen9 | ||
Hp Proliant Dl360 Gen9 | ||
Hp Proliant Dl380 Gen9 | ||
Hp Proliant Dl580 Gen9 | ||
Hp Proliant Ml10 Gen9 | =2 | |
Hp Proliant Ml110 Gen9 | ||
Hp Proliant Ml150 Gen9 | ||
Hp Proliant Ml30 Gen9 | =2 | |
Hp Proliant Ml350 Gen9 | ||
Hp Proliant Ws460c Gen9 | ||
Hp Proliant Xl170r Gen9 | ||
Hp Proliant Xl190r Gen9 | ||
Hp Proliant Xl230a Gen9 | ||
Hp Proliant Xl250a Gen9 | ||
Hp Proliant Xl730f Gen9 | ||
Hp Proliant Xl740f Gen9 | ||
Hp Proliant Xl750f Gen9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11982 is a remote cross site scripting vulnerability in HPE Integrated Lights-Out 4 (iLO 4) earlier than v2.61b for Gen9 servers and Integrated Lights-Out 5 (iLO 5) for Gen10 Servers earlier than version v1.39.
The HPE Integrated Lights-Out 4 (iLO 4) earlier than v2.61b for Gen9 servers and Integrated Lights-Out 5 (iLO 5) for Gen10 Servers earlier than version v1.39 are affected by CVE-2019-11982.
CVE-2019-11982 has a severity level of 8.3 (high).
To fix CVE-2019-11982, upgrade HPE Integrated Lights-Out 4 (iLO 4) to version v2.61b or later for Gen9 servers and upgrade Integrated Lights-Out 5 (iLO 5) to version v1.39 or later for Gen10 Servers.
You can find more information about CVE-2019-11982 [here](https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03917en_us).