CVE-2017-7421
Estado: ModificadaMedia (6.1)—
Reflected and stored Cross-Site Scripting (XSS, CWE-79) vulnerabilities in Directory Server (aka Enterprise Server Administration web UI) and ESMAC (aka Enterprise Server Monitor and Control) in Micro Focus Enterprise Developer and Enterprise Server 2.3 and earlier, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allow remote authenticated attackers to bypass protection mechanisms (CWE-693) and other security features.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Puntuación base: 6.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.26%
- Percentil entre todas las CVEs puntuadas: 69
- Fecha de la puntuación: 4/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (4)
CWE
- CWE-79
- CWE-79
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2017-7421",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.0",
"baseScore": 6.1,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security@opentext.com",
"affectedData": [
{
"vendor": "Micro Focus",
"product": "Micro Focus Enterprise Developer, Micro Focus Enterprise Server",
"versions": [
{
"status": "affected",
"version": "All versions before 2.3 Update 1, 2.3 Update 1 before Hotfix 8, 2.3 Update 2 before Hotfix 9"
}
]
}
]
}
],
"published": "2017-08-21T15:29:00.263",
"references": [
{
"url": "https://community.microfocus.com/microfocus/mainframe_solutions/enterprise_server/w/knowledge_base/29131/enterprise-server-security-fixes-july-2017",
"source": "security@opentext.com"
},
{
"url": "https://community.microfocus.com/microfocus/mainframe_solutions/enterprise_server/w/knowledge_base/29131/enterprise-server-security-fixes-july-2017",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "security@opentext.com",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Reflected and stored Cross-Site Scripting (XSS, CWE-79) vulnerabilities in Directory Server (aka Enterprise Server Administration web UI) and ESMAC (aka Enterprise Server Monitor and Control) in Micro Focus Enterprise Developer and Enterprise Server 2.3 and earlier, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allow remote authenticated attackers to bypass protection mechanisms (CWE-693) and other security features."
},
{
"lang": "es",
"value": "Las vulnerabilidades de cross-Site Scripting (XSS) reflejado y stored en Directory Server (también llamado Enterprise Server Administration web UI) y ESMAC (también llamado Enterprise Server Monitor and Control) en Micro Focus Enterprise Developer y Enterprise Server 2.3 y anteriores, 2.3 Update 1 en versiones anteriores a Hotfix 8, y 2.3 Update 2 en versiones anteriores a Hotfix 9 permiten que atacantes remotos autenticados omitan los mecanismos de protección (CWE-693) y otras características de seguridad."
}
],
"lastModified": "2026-06-17T01:24:19.167",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:microfocus:directory_server:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3FA6D858-2EBE-4EDB-9178-1FAB470F4E51"
},
{
"criteria": "cpe:2.3:a:microfocus:enterprise_developer:2.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E13FE8F0-D7FF-4C77-A0D9-DBE13222B2E4"
},
{
"criteria": "cpe:2.3:a:microfocus:enterprise_developer:2.3:update1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "ADAA9BF3-9B1F-44AE-9D74-B8747979DBA8"
},
{
"criteria": "cpe:2.3:a:microfocus:enterprise_developer:2.3:update2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4B18C3E3-494E-40A7-92F7-E7B95E9C094F"
},
{
"criteria": "cpe:2.3:a:microfocus:enterprise_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E6A661E8-AFD3-4B51-9E69-AD709A969ECC",
"versionEndIncluding": "2.3"
},
{
"criteria": "cpe:2.3:a:microfocus:enterprise_server:2.3:update1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E23C5342-8F45-4675-9401-EBC7287D65CD"
},
{
"criteria": "cpe:2.3:a:microfocus:enterprise_server:2.3:update2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6AD523A5-68BB-4397-945E-C95FD0E3229A"
},
{
"criteria": "cpe:2.3:a:microfocus:enterprise_server_monitor_and_control:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C94B4907-6212-448D-A8F0-E5A8FD701F58"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@opentext.com"
}