A potential security vulnerability has been identified in HPE Superdome Flex Servers. The vulnerability could be remotely exploited to allow Cross Site Scripting (XSS) because the Session Cookie is missing an HttpOnly Attribute. HPE has provided a firmware update to resolve the vulnerability in HPE Superdome Flex Servers.

Project Subscriptions

Vendors Products
Superdome Flex Subscribe
Superdome Flex 280 Subscribe
Superdome Flex 280 Firmware Subscribe
Superdome Flex Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2021-13387 A potential security vulnerability has been identified in HPE Superdome Flex Servers. The vulnerability could be remotely exploited to allow Cross Site Scripting (XSS) because the Session Cookie is missing an HttpOnly Attribute. HPE has provided a firmware update to resolve the vulnerability in HPE Superdome Flex Servers.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2024-08-03T20:26:25.641Z

Reserved: 2021-02-02T00:00:00

Link: CVE-2021-26589

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-10-19T15:15:07.533

Modified: 2024-11-21T05:56:32.500

Link: CVE-2021-26589

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses