CVE-2022-38754
CVE-2022-38754 - Micro Focus Operations Bridge Manager and OpsBridge Containerized - Cross Site Scripting (XSS)
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A potential vulnerability has been identified in Micro Focus Operations Bridge - Containerized. The vulnerability could be exploited by a malicious authenticated OBM (Operations Bridge Manager) user to run Java Scripts in the browser context of another OBM user. Please note: The vulnerability is only applicable if the Operations Bridge Manager capability is deployed. A potential vulnerability has been identified in Micro Focus Operations Bridge Manager (OBM). The vulnerability could be exploited by a malicious authenticated OBM user to run Java Scripts in the browser context of another OBM user. This issue affects: Micro Focus Micro Focus Operations Bridge Manager versions prior to 2022.11. Micro Focus Micro Focus Operations Bridge- Containerized versions prior to 2022.11.
Se ha identificado una vulnerabilidad potencial en Micro Focus Operations Bridge - Containerized. La vulnerabilidad podría ser aprovechada por un usuario malicioso de OBM (Operations Bridge Manager) autenticado para ejecutar Java Scripts en el contexto del navegador de otro usuario de OBM. Tenga en cuenta: la vulnerabilidad solo es aplicable si se implementa la capacidad de Operations Bridge Manager. Se ha identificado una vulnerabilidad potencial en Micro Focus Operations Bridge Manager (OBM). La vulnerabilidad podría ser aprovechada por un usuario malicioso de OBM autenticado para ejecutar Java Scripts en el contexto del navegador de otro usuario de OBM. Este problema afecta a: Versiones de Micro Focus Micro Focus Operations Bridge Manager anteriores a 2022.11. Micro Focus Micro Focus Operations Bridge: versiones en contenedores anteriores a 2022.11.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-08-25 CVE Reserved
- 2022-12-08 CVE Published
- 2024-08-03 CVE Updated
- 2024-10-24 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (3)
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Microfocus Search vendor "Microfocus" | Operations Bridge Search vendor "Microfocus" for product "Operations Bridge" | < 2022.11 Search vendor "Microfocus" for product "Operations Bridge" and version " < 2022.11" | - |
Affected
| ||||||
Microfocus Search vendor "Microfocus" | Operations Bridge Manager Search vendor "Microfocus" for product "Operations Bridge Manager" | < 2022.11 Search vendor "Microfocus" for product "Operations Bridge Manager" and version " < 2022.11" | - |
Affected
|