CVE-2017-8991

MEDIUM

HPE CentralView Fraud Risk Management < 6.1 - Cross-Site Scripting

Title source: llm
STIX 2.1

Description

HPE has identified a cross site scripting (XSS) vulnerability in HPE CentralView Fraud Risk Management earlier than version CV 6.1. This issue is resolved in HF16 for HPE CV 6.1 or subsequent version.

References (1)

Core 1

Scores

CVSS v3 5.4
EPSS 0.0030
EPSS Percentile 53.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
hp/centralview_fraud_risk_management < 6.1
Published Aug 06, 2018
Tracked Since Feb 18, 2026