CVE-2021-26587
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Exploitability: 2.3 / Impact: 3.7
Source: NVD
Description
A potential DOM-based Cross Site Scripting security vulnerability has been identified in HPE StoreOnce. The vulnerability could be remotely exploited to cause an elevation of privilege leading to partial impact to confidentiality, availability, and integrity. HPE has made the following software update - HPE StoreOnce 4.3.0, to resolve the vulnerability in HPE StoreOnce.
Affected (6)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 4.2.3 |
| Running on/with | Platform Versions |
|---|---|
Hpe Storeonce 5200 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 4.2.3 |
| Running on/with | Platform Versions |
|---|---|
Hpe Storeonce 5650 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 4.2.3 |
| Running on/with | Platform Versions |
|---|---|
Hpe Storeonce 5250 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 4.2.3 |
| Running on/with | Platform Versions |
|---|---|
Hpe Storeonce 3640 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 4.2.3 |
| Running on/with | Platform Versions |
|---|---|
Hpe Storeonce 3620 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 4.2.3 |
| Running on/with | Platform Versions |
|---|---|
Hpe Storeonce Vsa 4tb | All versions |
References (2)
Source: security-alert@hpe.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.