Impact
The cross‑site scripting flaw in HPE OneView can allow an attacker to inject malicious scripts into the web interface, potentially hijacking user sessions or enabling other unauthorized actions. This vulnerability could lead to compromise of authentication credentials, unauthorized data access, or manipulation of system settings.
Affected Systems
Hewlett Packard Enterprise’s HPE OneView management platform is affected. No specific version information is provided in the advisory.
Risk and Exploitability
The vulnerability is exploitable via the web UI of HPE OneView, where a non‑authenticated or authenticated user could craft a malicious request. The CVSS score of 8.2 indicates high severity, while the EPSS score of less than 1% suggests limited likelihood of widespread exploitation. The flaw is not listed in the CISA Known Exploited Vulnerabilities catalog, but the potential for session hijacking remains a significant risk.
OpenCVE Enrichment