ZeroHour

CVE-2021-26589

CVSS 3.1
6.1 medium
EPSS
<1%p44
Published
()
Modified
Description

A potential security vulnerability has been identified in HPE Superdome Flex Servers. The vulnerability could be remotely exploited to allow Cross Site Scripting (XSS) because the Session Cookie is missing an HttpOnly Attribute. HPE has provided a firmware update to resolve the vulnerability in HPE Superdome Flex Servers.

Vendors
hpe
Products
superdome flex firmware, superdome flex 280 firmware
Weakness
CWE-732
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.