RULE(RULE ID:321991)

Rule General Information
Release Date: 2019-06-25
Rule Name: HP System Management Homepage red2301.html RedirectUrl Cross Site Scripting Vulnerability (CVE-2014-2640)
Severity:
CVE ID:
Rule Protection Details
Description: Cross-site scripting (XSS) vulnerability in HP System Management Homepage (SMH) before 7.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Impact: An attacker can conduct a cross-site scripting attack to inject malicious client-side scripts into web pages viewed by other users, or to bypass access controls such as the same-origin policy, if affected version is installed.
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others
Reference: SecurityTrackerID:1030960
http://www.kb.cert.org/vuls/id/125228
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04463322