CVE-2021-38123: Medium severity MicroFocus Network Automation vulnerability
Open Redirect vulnerability in Micro Focus Network Automation, affecting Network Automation versions 10.4x, 10.5x, 2018.05, 2018.11, 2019.05, 2020.02, 2020.08, 2020.11, 2021.05. The vulnerability could allow redirect users to malicious websites after authentication.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict access so that only trusted users can reach Network Automation URLs and limit exposure of the application from untrusted networks until a vendor fix is applied (mitigates risk of users being redirected to malicious websites after authentication).
Event History
Frequently Asked Questions
What is CVE-2021-38123?
CVE-2021-38123 is an Open Redirect vulnerability in Micro Focus Network Automation.
Which versions of Micro Focus Network Automation are affected by CVE-2021-38123?
Micro Focus Network Automation versions 10.4x, 10.5x, 2018.05, 2018.11, 2019.05, 2020.02, 2020.08, 2020.11, and 2021.05 are affected by CVE-2021-38123.
What is the severity of CVE-2021-38123?
CVE-2021-38123 has a severity score of 6.1 (medium).
How does CVE-2021-38123 impact users?
CVE-2021-38123 can redirect users to malicious websites after authentication.
How can I fix CVE-2021-38123?
To fix CVE-2021-38123, update to a patched version of Micro Focus Network Automation.