{"$ref":"https://www.cert.ssi.gouv.fr/openapi.json","affected_systems":[{"description":"HP OpenView Network Node Manager (OP NNM) version 6.41 ;","product":{"name":"N/A","vendor":{"name":"N/A","scada":false}}},{"description":"HP OpenView Network Node Manager (OP NNM) version 7.01 ;","product":{"name":"N/A","vendor":{"name":"N/A","scada":false}}},{"description":"HP OpenView Network Node Manager (OP NNM) version 7.51.","product":{"name":"N/A","vendor":{"name":"N/A","scada":false}}}],"affected_systems_content":null,"content":"## Description\n\nUn d\u00e9faut de contr\u00f4le d'une variable permet \u00e0 un utilisateur distant de\nr\u00e9aliser une injection de code indirecte (Cross Site Scripting), par le\nbiais d'une page construite de fa\u00e7on particuli\u00e8re.\n\n## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l'\u00e9diteur pour l'obtention des\ncorrectifs (cf. section Documentation).\n","cves":[],"links":[{"title":"Bulletin de s\u00e9curit\u00e9 HP c01218087 du 28 novembre 2007 :","url":"http://itrc.hp.com/service/cki/docDisplay.do?docId=c01218087"}],"reference":"CERTA-2007-AVI-522","revisions":[{"description":"version initiale.","revision_date":"2007-12-05T00:00:00.000000"}],"risks":[{"description":"Injection de code indirecte (cross site scripting)"}],"summary":"Une vuln\u00e9rabilit\u00e9 de type injection de code indirecte (Cross Site\nScripting) a \u00e9t\u00e9 d\u00e9couverte dans HP OpenView Network Node Manager (OP\nNNM).\n","title":"Vuln\u00e9rabilit\u00e9 dans HP OpenView Network Node Manager","vendor_advisories":[{"published_at":null,"title":"Bulletin de s\u00e9curit\u00e9 HP HPSBMA02283 du 28 novembre 2007","url":null}]}
