Impact
A cross‑site scripting flaw in HPE OneView allows an attacker to inject malicious scripts into the web interface. The vulnerability is classified as CWE-79, and if exploited it can lead to session hijacking, data theft, or execution of other unauthorized actions on the system.
Affected Systems
The affected product is Hewlett Packard Enterprise HPE OneView. No specific product version is listed in the advisory; the flaw appears to apply to all releases that contain the described XSS vulnerability.
Risk and Exploitability
The CVSS score of 8.2 indicates a high severity. EPSS data is not available, so the likelihood of exploitation is unknown. The vulnerability is not included in the CISA KEV catalog. The likely attack vector is remote, requiring an attacker to send crafted input to the OneView web interface from a network location that can access the management portal. No authentication step is required for the vulnerability to be triggered, but the attacker would need a user session or permission to execute the injected script.
OpenCVE Enrichment