VYPR
Unrated severityNVD Advisory· Published May 22, 2018· Updated Sep 16, 2024

MFSBGN03806 rev.1 - HP Network Automation Software, Network Operations Management (NOM) Suite, Multiple Vulnerabilities

CVE-2018-6492

Description

Persistent XSS and non-persistent HTML Injection vulnerabilities in HP Network Operations Management Ultimate and Network Automation allow remote exploitation.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Persistent XSS and non-persistent HTML Injection vulnerabilities in HP Network Operations Management Ultimate and Network Automation allow remote exploitation.

Vulnerability

Persistent cross-site scripting (XSS) and non-persistent HTML injection vulnerabilities exist in HP Network Operations Management Ultimate (versions 2017.07, 2017.11, 2018.02) and Network Automation (versions 10.00, 10.10, 10.11, 10.20, 10.30, 10.40, 10.50). The vulnerabilities reside in the web interface of these products, allowing an attacker to inject malicious scripts or HTML that are either stored and later executed (persistent XSS) or reflected immediately (non-persistent HTML injection) [1].

Exploitation

An attacker with network access to the affected product's web interface can exploit these vulnerabilities without requiring authentication. For persistent XSS, the attacker submits crafted input that is stored by the application and subsequently rendered to other users. For non-persistent HTML injection, the attacker crafts a malicious link or request that reflects injected HTML in the response. No user interaction is required for the stored variant, while the reflected variant may require the victim to click a crafted link [1].

Impact

Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's browser (persistent XSS), potentially leading to session hijacking, defacement, or theft of sensitive data. Non-persistent HTML injection enables the attacker to inject arbitrary HTML content, which can be used to spoof page content or trick users into performing actions. The attacker gains the ability to impersonate the victim or perform actions on behalf of an authenticated user [1].

Mitigation

Micro Focus has released a security bulletin (KM03158014) addressing these vulnerabilities. Users should upgrade to the latest patched versions as specified in the bulletin. No workarounds are documented; applying the vendor-supplied patch is the recommended mitigation [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3
  • 2017.07, 2017.11, 2018.02+ 1 more
    • (no CPE)range: 2017.07, 2017.11, 2018.02
    • (no CPE)range: 2017.07, 2017.11, 2018.02
  • Micro Focus/Network Automationv5
    Range: 10.00, 10.10, 10.11, 10.20, 10.30, 10.40, 10.50

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

3

News mentions

0

No linked articles in our index yet.