Cross-site scripting (XSS) vulnerability in the web-based management interface of Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) versions before 7.4.2b, 8.1.2 and 8.2.0 could allow remote attackers to execute arbitrary code or access sensitive browser-based information.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 03:29
Type | Values Removed | Values Added |
---|---|---|
References | () https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst03851en_us - | |
References | () https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2018-525 - |
Information
Published : 2018-02-08 22:29
Updated : 2024-11-21 03:29
NVD link : CVE-2017-6225
Mitre link : CVE-2017-6225
CVE.ORG link : CVE-2017-6225
JSON object : View
Products Affected
broadcom
- fabric_operating_system
brocade
- fabric_os
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')