MEDIUM
Cross Site scripting vulnerability on Micro Focus Enterprise Server and Enterprise developer, affecting all versions prior to version 5.0 Patch Update 8
Published May 18, 2020
5.4
MEDIUMCVSS 3.1
EPSS 0.51%
Description
Cross Site scripting vulnerability on Micro Focus Enterprise Server and Enterprise developer, affecting all versions prior to version 5.0 Patch Update 8. The vulnerability could allow an attacker to trigger administrative actions when an administrator viewed malicious data left by the attacker (stored XSS) or followed a malicious link (reflected XSS).
Affected products
- Vendor n/a Product Enterprise Server and Enterprise developer. Defaultunknown
Affected
- All versions prior to version 5.0 Patch Update 8.
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| n/a | Enterprise Server and Enterprise developer. | unknown | Affected
|
OR
- 5.0
- 5.0
- 5.0
- 5.0
- 5.0
- 5.0
- 5.0
- 5.0
- 5.0
- 5.0
- 5.0
- 5.0
- 5.0
- 5.0
- 5.0
- 5.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-30330 Advisory
- https://softwaresupport.softwaregrp.com/doc/KM03640252 x_refsource_MISC
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-30330 | Advisory | |
| https://softwaresupport.softwaregrp.com/doc/KM03640252 | x_refsource_MISC |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner microfocus
Published May 18, 2020
Updated Aug 4, 2024
Reserved Mar 1, 2020
Link CVE-2020-9524
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data