CVE-2021-26582: XSS
Published Apr 15, 2021
·Updated
A security vulnerability in HPE IceWall SSO Domain Gateway Option (Dgfw) module version 10.0 on RHEL 5/6/7, version 10.0 on HP-UX 11i v3, version 10.0 on Windows and 11.0 on Windows could be exploited remotely to allow cross-site scripting (XSS).
Affected Software
7 affected components
HP Icewall Sso Dgfw=10.0
HP Icewall Sso Dgfw=11.0
Microsoft Windows
redhat Enterprise Linux=5.0
redhat Enterprise Linux=6.0
redhat Enterprise Linux=7.0
HP HP-UX=11i-v3.0
Event History
Apr 15, 2021
CVE Published
via MITRE·05:50 PM
Data Sourced
via MITRE·05:50 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-26582?
The severity of CVE-2021-26582 is rated as medium with a CVSS score of 6.1.
2
How can the CVE-2021-26582 vulnerability be exploited?
CVE-2021-26582 can be exploited remotely to allow cross-site scripting (XSS) attacks.
3
Which versions of HPE IceWall SSO Dgfw are affected by CVE-2021-26582?
Versions 10.0 and 11.0 of HPE IceWall SSO Dgfw are affected by CVE-2021-26582.
4
Is Microsoft Windows affected by CVE-2021-26582?
Microsoft Windows is not vulnerable to CVE-2021-26582.
5
How can I mitigate the CVE-2021-26582 vulnerability?
To mitigate CVE-2021-26582, apply the necessary patches and updates provided by the vendor.