Medium severity6.5NVD Advisory· Published Sep 27, 2021· Updated Jun 17, 2026
CVE-2021-26587
CVE-2021-26587
Description
A potential DOM-based Cross Site Scripting security vulnerability has been identified in HPE StoreOnce. The vulnerability could be remotely exploited to cause an elevation of privilege leading to partial impact to confidentiality, availability, and integrity. HPE has made the following software update - HPE StoreOnce 4.3.0, to resolve the vulnerability in HPE StoreOnce.
Affected products
7- cpe:2.3:o:hpe:storeonce_vsa_4tb_firmware:*:*:*:*:*:*:*:*Range: <=4.2.3
- Range: before 4.3.0
Patches
Vulnerability mechanics
References
1- support.hpe.com/hpsc/doc/public/displaynvdVendor Advisory
News mentions
0No linked articles in our index yet.