CVE-2021-26589
Last modified
CVE-2021-26589 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. A potential security vulnerability has been identified in HPE Superdome Flex Servers. The vulnerability could be remotely exploited to allow Cross Site Scripting (XSS) because the Session Cookie is missing an HttpOnly Attribute. EPSS estimates a 0.53% chance of exploitation in the next 30 days.
Description
A potential security vulnerability has been identified in HPE Superdome Flex Servers. The vulnerability could be remotely exploited to allow Cross Site Scripting (XSS) because the Session Cookie is missing an HttpOnly Attribute. HPE has provided a firmware update to resolve the vulnerability in HPE Superdome Flex Servers.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hpe | Superdome Flex Firmware | < 3.40.106 |
| Hpe | Superdome Flex 280 Firmware | < 3.40.106 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-26589?
How severe is CVE-2021-26589?
How do I fix CVE-2021-26589?
Are you affected by CVE-2021-26589?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
