Vulnerability Note VU#292457

HP System Management Homepage cross-site scripting vulnerability

Original Release date: 05 Jun 2007 | Last revised: 05 Jun 2007

Overview

The HP System Management Homepage contains a cross-site scripting vulnerability.

Description

The HP System Management Homepage (SMH) server is a web-based interface that can manage HP servers running the Microsoft Windows or Linux operating systems.

The SMH contains an unspecified cross-site scripting vulnerability.

Impact

An attacker may be able to obtain sensitive data, corrupt or steal cookies, or take any action that the SMH server can.

Solution

Upgrade
HP has released SMH version 2.1.8-17 to address this issue.


Restrict access

Restricting network access to the SMH server using a firewall or access control lists may mitigate this vulnerability.

Systems Affected (Learn More)

VendorStatusDate NotifiedDate Updated
Hewlett-Packard CompanyAffected-05 Jun 2007
If you are a vendor and your product is affected, let us know.

CVSS Metrics (Learn More)

Group Score Vector
Base N/A N/A
Temporal N/A N/A
Environmental N/A N/A

References

Credit

Thanks to HP for information that was used in this report.

This document was written by Ryan Giobbi.

Other Information

  • CVE IDs: Unknown
  • Date Public: 05 Jun 2007
  • Date First Published: 05 Jun 2007
  • Date Last Updated: 05 Jun 2007
  • Severity Metric: 0.13
  • Document Revision: 12

Feedback

If you have feedback, comments, or additional information about this vulnerability, please send us email.