First published: Wed Jul 08 2020(Updated: )
A security vulnerability in HPE IceWall SSO Dfw and Dgfw (Domain Gateway Option) could be exploited remotely to cause a remote cross-site scripting (XSS). HPE has provided the following information to resolve this vulnerability in HPE IceWall SSO DFW and Dgfw: https://www.hpe.com/jp/icewall_patchaccess
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hp Icewall Sso Dfw | =11.0 | |
Hp Icewall Sso Dgfw | =11.0 | |
Microsoft Windows | ||
Red Hat Enterprise Linux |
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbmu04011en_us
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-7140 is classified as a high-severity vulnerability due to its potential to allow remote cross-site scripting attacks.
To remediate CVE-2020-7140, users should apply the patches provided by HPE for IceWall SSO DFW and Dgfw.
CVE-2020-7140 affects version 11.0 of both HPE IceWall SSO DFW and Dgfw.
Yes, CVE-2020-7140 can be exploited remotely, allowing attackers to perform cross-site scripting attacks.
If immediate patching is not possible for CVE-2020-7140, consider implementing web application firewalls to help filter out malicious scripts.