CVE-2021-22499Cross-site Scripting in Application Performance Management

Severity
4.8MEDIUMNVD
EPSS
0.2%
top 56.81%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 6
Latest updateMay 24

Description

Persistent Cross-Site scripting vulnerability in Micro Focus Application Performance Management product, affecting versions 9.40, 9.50 and 9.51. The vulnerability could allow persistent XSS attack.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:NExploitability: 1.7 | Impact: 2.7

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-8wxp-wp4j-j684: Persistent Cross-Site scripting vulnerability in Micro Focus Application Performance Management product, affecting versions 92022-05-24
CVEList
CVE-2021-22499: Persistent Cross-Site scripting vulnerability in Micro Focus Application Performance Management product, affecting versions 92021-02-06
CVE-2021-22499 — Cross-site Scripting | cvebase