CVE-2018-6492

Persistent Cross-Site Scripting, and non-persistent HTML Injection in HP Network Operations Management Ultimate, version 2017.07, 2017.11, 2018.02 and in Network Automation, version 10.00, 10.10, 10.11, 10.20, 10.30, 10.40, 10.50. This vulnerability could be remotely exploited to allow persistent cross-site scripting, and non-persistent HTML Injection.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.7 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
microfocusCNA
4.7 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 61%
VendorProductVersion
hpnetwork_operations_management_ultimate
2017.07
hpnetwork_operations_management_ultimate
2017.11
hpnetwork_operations_management_ultimate
2018.02
hpnetwork_automation
10.00
hpnetwork_automation
10.10
hpnetwork_automation
10.11
hpnetwork_automation
10.20
hpnetwork_automation
10.30
hpnetwork_automation
10.40
hpnetwork_automation
10.50
𝑥
= Vulnerable software versions