// For flags

CVE-2014-7896

 

Severity Score

4.3
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Multiple cross-site scripting (XSS) vulnerabilities in HP XP P9000 Command View Advanced Edition Software Online Help, as used in HP Device Manager 6.x through 8.x before 8.1.2-00, HP XP P9000 Tiered Storage Manager 6.x through 8.x before 8.1.2-00, HP XP P9000 Replication Manager 6.x and 7.x before 7.6.1-06, and HP XP7 Global Link Manager Software (aka HGLM) 6.x through 8.x before 8.1.2-00, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Múltiples vulnerabilidades de XSS en HP XP P9000 Command View Advanced Edition Software Online Help, utilizado en HP Device Manager 6.x hasta 8.x anterior a 8.1.2-00, HP XP P9000 Tiered Storage Manager 6.x hasta 8.x anterior a 8.1.2-00, HP XP P9000 Replication Manager 6.x y 7.x anterior a 7.6.1-06, y HP XP7 Global Link Manager Software (también conocido como HGLM) 6.x hasta 8.x anterior a 8.1.2-00, permiten a atacantes remotos inyectar secuencias de comandos web arbitrarios o HTML a través de vectores no especificados.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2014-10-06 CVE Reserved
  • 2015-03-02 CVE Published
  • 2023-03-07 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Hp
Search vendor "Hp"
Xp P9000 Device Manager
Search vendor "Hp" for product "Xp P9000 Device Manager"
<= 8.1.1
Search vendor "Hp" for product "Xp P9000 Device Manager" and version " <= 8.1.1"
-
Affected
Hp
Search vendor "Hp"
Xp P9000 Replication Manager
Search vendor "Hp" for product "Xp P9000 Replication Manager"
<= 7.6.1
Search vendor "Hp" for product "Xp P9000 Replication Manager" and version " <= 7.6.1"
-
Affected
Hp
Search vendor "Hp"
Xp P9000 Tiered Storage Manager
Search vendor "Hp" for product "Xp P9000 Tiered Storage Manager"
<= 8.1.1
Search vendor "Hp" for product "Xp P9000 Tiered Storage Manager" and version " <= 8.1.1"
-
Affected
Hp
Search vendor "Hp"
Xp7 Global Link Manager Software
Search vendor "Hp" for product "Xp7 Global Link Manager Software"
<= 8.1.1
Search vendor "Hp" for product "Xp7 Global Link Manager Software" and version " <= 8.1.1"
-
Affected