← Back

CVE-2017-7421

nvd nist
Published: Aug 21, 2017Modified: May 13, 2026

JSON object

Loading...
6.1
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

Reflected and stored Cross-Site Scripting (XSS, CWE-79) vulnerabilities in Directory Server (aka Enterprise Server Administration web UI) and ESMAC (aka Enterprise Server Monitor and Control) in Micro Focus Enterprise Developer and Enterprise Server 2.3 and earlier, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allow remote authenticated attackers to bypass protection mechanisms (CWE-693) and other security features.

Affected (8)

4 products
Directory Server
Enterprise Developer
Enterprise Server
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
All versions
Microfocus
Version 2.3
Version 2.3 update1
Version 2.3 update2
Microfocus
Up to 2.3
Version 2.3 update1
Version 2.3 update2
All versions

Timeline

No history available yet.