Vulnerability Description
Cross-site scripting (XSS) vulnerability in HPE Network Node Manager i (NNMi) 9.20, 9.23, 9.24, 9.25, 10.00, and 10.01 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-2010.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hp | Network Node Manager I | 9.20 |
Related Weaknesses (CWE)
References
- http://www.securitytracker.com/id/1035767
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-cPatchVendor Advisory
- http://www.securitytracker.com/id/1035767
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-cPatchVendor Advisory
FAQ
What is CVE-2016-2011?
CVE-2016-2011 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Cross-site scripting (XSS) vulnerability in HPE Network Node Manager i (NNMi) 9.20, 9.23, 9.24, 9.25, 10.00, and 10.01 allows remote authenticated users to inject arbitrary web script or HTML via unsp...
How severe is CVE-2016-2011?
CVE-2016-2011 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-2011?
Check the references section above for vendor advisories and patch information. Affected products include: Hp Network Node Manager I.