CVE-2021-26589
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD
Description
A potential security vulnerability has been identified in HPE Superdome Flex Servers. The vulnerability could be remotely exploited to allow Cross Site Scripting (XSS) because the Session Cookie is missing an HttpOnly Attribute. HPE has provided a firmware update to resolve the vulnerability in HPE Superdome Flex Servers.
Affected (2)
Products: Hpe: Superdome Flex Firmware, Superdome Flex 280 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.40.106 |
| Running on/with | Platform Versions |
|---|---|
Hpe Superdome Flex | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.40.106 |
| Running on/with | Platform Versions |
|---|---|
Hpe Superdome Flex 280 | All versions |
References (2)
Source: security-alert@hpe.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.