CVE-2017-7421
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Reflected and stored Cross-Site Scripting (XSS, CWE-79) vulnerabilities in Directory Server (aka Enterprise Server Administration web UI) and ESMAC (aka Enterprise Server Monitor and Control) in Micro Focus Enterprise Developer and Enterprise Server 2.3 and earlier, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allow remote authenticated attackers to bypass protection mechanisms (CWE-693) and other security features.
Las vulnerabilidades de cross-Site Scripting (XSS) reflejado y stored en Directory Server (también llamado Enterprise Server Administration web UI) y ESMAC (también llamado Enterprise Server Monitor and Control) en Micro Focus Enterprise Developer y Enterprise Server 2.3 y anteriores, 2.3 Update 1 en versiones anteriores a Hotfix 8, y 2.3 Update 2 en versiones anteriores a Hotfix 9 permiten que atacantes remotos autenticados omitan los mecanismos de protección (CWE-693) y otras características de seguridad.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-04-05 CVE Reserved
- 2017-08-21 CVE Published
- 2024-05-01 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://community.microfocus.com/microfocus/mainframe_solutions/enterprise_server/w/knowledge_base/29131/enterprise-server-security-fixes-july-2017 | X_refsource_misc |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Microfocus Search vendor "Microfocus" | Directory Server Search vendor "Microfocus" for product "Directory Server" | - | - |
Affected
| ||||||
Microfocus Search vendor "Microfocus" | Enterprise Developer Search vendor "Microfocus" for product "Enterprise Developer" | 2.3 Search vendor "Microfocus" for product "Enterprise Developer" and version "2.3" | - |
Affected
| ||||||
Microfocus Search vendor "Microfocus" | Enterprise Developer Search vendor "Microfocus" for product "Enterprise Developer" | 2.3 Search vendor "Microfocus" for product "Enterprise Developer" and version "2.3" | update1 |
Affected
| ||||||
Microfocus Search vendor "Microfocus" | Enterprise Developer Search vendor "Microfocus" for product "Enterprise Developer" | 2.3 Search vendor "Microfocus" for product "Enterprise Developer" and version "2.3" | update2 |
Affected
| ||||||
Microfocus Search vendor "Microfocus" | Enterprise Server Search vendor "Microfocus" for product "Enterprise Server" | <= 2.3 Search vendor "Microfocus" for product "Enterprise Server" and version " <= 2.3" | - |
Affected
| ||||||
Microfocus Search vendor "Microfocus" | Enterprise Server Search vendor "Microfocus" for product "Enterprise Server" | 2.3 Search vendor "Microfocus" for product "Enterprise Server" and version "2.3" | update1 |
Affected
| ||||||
Microfocus Search vendor "Microfocus" | Enterprise Server Search vendor "Microfocus" for product "Enterprise Server" | 2.3 Search vendor "Microfocus" for product "Enterprise Server" and version "2.3" | update2 |
Affected
| ||||||
Microfocus Search vendor "Microfocus" | Enterprise Server Monitor And Control Search vendor "Microfocus" for product "Enterprise Server Monitor And Control" | - | - |
Affected
|