← Back

CVE-2021-26589

nvd nist
Published: Oct 19, 2021Modified: Nov 21, 2024

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

A potential security vulnerability has been identified in HPE Superdome Flex Servers. The vulnerability could be remotely exploited to allow Cross Site Scripting (XSS) because the Session Cookie is missing an HttpOnly Attribute. HPE has provided a firmware update to resolve the vulnerability in HPE Superdome Flex Servers.

Affected (2)

2 products
Superdome Flex Firmware
Superdome Flex 280 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 3.40.106
Running on/withPlatform Versions
Hpe
Superdome Flex
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 3.40.106
Running on/withPlatform Versions
Hpe
Superdome Flex 280
All versions

Timeline

No history available yet.