5.4
CVE-2020-9524
- EPSS 0.21%
- Published 18.05.2020 14:15:12
- Last modified 21.11.2024 05:40:48
- Source security@opentext.com
- Teams watchlist Login
- Open Login
Cross Site scripting vulnerability on Micro Focus Enterprise Server and Enterprise developer, affecting all versions prior to version 5.0 Patch Update 8. The vulnerability could allow an attacker to trigger administrative actions when an administrator viewed malicious data left by the attacker (stored XSS) or followed a malicious link (reflected XSS).
Data is provided by the National Vulnerability Database (NVD)
Microfocus ≫ Enterprise Developer Version5.0 Update-
Microfocus ≫ Enterprise Developer Version5.0 Updatep1
Microfocus ≫ Enterprise Developer Version5.0 Updatep2
Microfocus ≫ Enterprise Developer Version5.0 Updatep3
Microfocus ≫ Enterprise Developer Version5.0 Updatep4
Microfocus ≫ Enterprise Developer Version5.0 Updatep5
Microfocus ≫ Enterprise Developer Version5.0 Updatep6
Microfocus ≫ Enterprise Developer Version5.0 Updatep7
Microfocus ≫ Enterprise Server Version5.0 Update-
Microfocus ≫ Enterprise Server Version5.0 Updatep1
Microfocus ≫ Enterprise Server Version5.0 Updatep2
Microfocus ≫ Enterprise Server Version5.0 Updatep3
Microfocus ≫ Enterprise Server Version5.0 Updatep4
Microfocus ≫ Enterprise Server Version5.0 Updatep5
Microfocus ≫ Enterprise Server Version5.0 Updatep6
Microfocus ≫ Enterprise Server Version5.0 Updatep7
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.21% | 0.399 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 5.4 | 2.3 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
|
nvd@nist.gov | 3.5 | 6.8 | 2.9 |
AV:N/AC:M/Au:S/C:N/I:P/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.