CVE-2017-7421

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
21/08/2017
Last modified:
20/04/2025

Description

Reflected and stored Cross-Site Scripting (XSS, CWE-79) vulnerabilities in Directory Server (aka Enterprise Server Administration web UI) and ESMAC (aka Enterprise Server Monitor and Control) in Micro Focus Enterprise Developer and Enterprise Server 2.3 and earlier, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allow remote authenticated attackers to bypass protection mechanisms (CWE-693) and other security features.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:microfocus:directory_server:-:*:*:*:*:*:*:*
cpe:2.3:a:microfocus:enterprise_developer:2.3:*:*:*:*:*:*:*
cpe:2.3:a:microfocus:enterprise_developer:2.3:update1:*:*:*:*:*:*
cpe:2.3:a:microfocus:enterprise_developer:2.3:update2:*:*:*:*:*:*
cpe:2.3:a:microfocus:enterprise_server:*:*:*:*:*:*:*:* 2.3 (including)
cpe:2.3:a:microfocus:enterprise_server:2.3:update1:*:*:*:*:*:*
cpe:2.3:a:microfocus:enterprise_server:2.3:update2:*:*:*:*:*:*
cpe:2.3:a:microfocus:enterprise_server_monitor_and_control:-:*:*:*:*:*:*:*