CVE-2020-9524: XSS
Cross Site scripting vulnerability on Micro Focus Enterprise Server and Enterprise developer, affecting all versions prior to version 5.0 Patch Update 8. The vulnerability could allow an attacker to trigger administrative actions when an administrator viewed malicious data left by the attacker (stored XSS) or followed a malicious link (reflected XSS).
Affected Software
Event History
Frequently Asked Questions
What is the CVE ID for this vulnerability?
The CVE ID for this vulnerability is CVE-2020-9524.
What software versions are affected by this vulnerability?
Micro Focus Enterprise Server and Enterprise Developer versions prior to version 5.0 Patch Update 8 are affected.
How does this vulnerability impact the affected software?
This vulnerability allows an attacker to trigger administrative actions when an administrator views malicious data left by the attacker.
What is the severity rating of CVE-2020-9524?
The severity rating of CVE-2020-9524 is medium, with a CVSS score of 5.4.
How can I fix this vulnerability?
To fix this vulnerability, you should update Micro Focus Enterprise Server and Enterprise Developer to version 5.0 Patch Update 8 or later.