CVE-2020-7140: XSS
A security vulnerability in HPE IceWall SSO Dfw and Dgfw (Domain Gateway Option) could be exploited remotely to cause a remote cross-site scripting (XSS). HPE has provided the following information to resolve this vulnerability in HPE IceWall SSO DFW and Dgfw: https://www.hpe.com/jp/icewallpatchaccess
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-7140?
CVE-2020-7140 is classified as a high-severity vulnerability due to its potential to allow remote cross-site scripting attacks.
How do I fix CVE-2020-7140?
To remediate CVE-2020-7140, users should apply the patches provided by HPE for IceWall SSO DFW and Dgfw.
Which versions of HPE IceWall SSO are affected by CVE-2020-7140?
CVE-2020-7140 affects version 11.0 of both HPE IceWall SSO DFW and Dgfw.
Can CVE-2020-7140 be exploited remotely?
Yes, CVE-2020-7140 can be exploited remotely, allowing attackers to perform cross-site scripting attacks.
Is there an alternative mitigation for CVE-2020-7140 if I can't patch immediately?
If immediate patching is not possible for CVE-2020-7140, consider implementing web application firewalls to help filter out malicious scripts.