MEDIUM
Stored cross site scripting
Published Feb 26, 2021
5.5
MEDIUMCVSS 3.1
EPSS 0.32%
Description
Micro Focus Solutions Business Manager versions prior to 11.7.1 are vulnerable to stored XSS. The application reflects previously stored user input without encoding.
Affected products
-
Affected
- < 11.7.1
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Micro Focus | Solutions Business Manager | unknown | Affected
|
- < 11.7.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade SBM to 11.7.1 or later
Weaknesses (1)
References (2)
- http://knowledgebase.serena.com/resources/sites/KNOWLEDGEBASE/content/live/SOLUTIONS/142000/S142001/en_US/sbm_11.7.1_security_bulletin.htm x_refsource_CONFIRM
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-8613 Advisory
| Link | Providers | Tags |
|---|---|---|
| http://knowledgebase.serena.com/resources/sites/KNOWLEDGEBASE/content/live/SOLUTIONS/142000/S142001/en_US/sbm_11.7.1_security_bulletin.htm | x_refsource_CONFIRM | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-8613 | Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner microfocus
Published Feb 26, 2021
Updated Sep 16, 2024
Reserved Nov 13, 2019
Link CVE-2019-18942
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data