microfocus solutions-business-manager CVE-2019-18942 is a vulnerability in Micro Focus Solutions Business Manager
Published on February 26, 2021

Stored cross site scripting
Micro Focus Solutions Business Manager versions prior to 11.7.1 are vulnerable to stored XSS. The application reflects previously stored user input without encoding.

NVD

Vulnerability Analysis

Attack Vector:
ADJACENT_NETWORK
Attack Complexity:
LOW
Privileges Required:
LOW
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
LOW
Integrity Impact:
LOW
Availability Impact:
LOW

Weakness Type

What is a XSS Vulnerability?

The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

CVE-2019-18942 has been classified to as a XSS vulnerability or weakness.


Products Associated with CVE-2019-18942

Want to know whenever a new CVE is published for Micro Focus Solutions Business Manager? stack.watch will email you.

 

Affected Versions

Micro Focus Solutions Business Manager Version < 11.7.1 is affected by CVE-2019-18942

Exploit Probability

EPSS
0.07%
Percentile
21.70%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.