- Community Home
- >
- Storage
- >
- Entry Storage Systems
- >
- MSA Storage
- >
- HP MSA 2060 Vulnerability Assessment
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Discussions
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-05-2023 09:27 PM - last edited on 01-12-2023 12:07 AM by support_s
01-05-2023 09:27 PM - last edited on 01-12-2023 12:07 AM by support_s
HP MSA 2060 Vulnerability Assessment
Hi Admin
We have one "Vulnerability Assessment Report" about HP MSA 2060 at controller B
JQuery 1.2 < 3.5.0 Multiple XSS
JQuery Detection
jQuery UI Detection
then "Vulnerability Assessment Report" about HP MSA 2060 at controller A doen't any alert.
I didn't find any setting about web, How can I check ?
- Tags:
- msa
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-10-2023 04:05 AM
01-10-2023 04:05 AM
Re: HP MSA 2060 Vulnerability Assessment
Hi,
I guess the vulnerability assessment is related to CVE-2020-11022.
This has been patched in MSA controller firmware version IN110R001/IN110P001.
IN110P001 is the latest version firmware.
IN110R001 advisory:
https://support.hpe.com/hpesc/public/docDisplay?docId=a00116687en_us&docLocale=en_US
MSA controllers feature JQuery 3.2.1 with the patches to mitigate CVE-2020-11022.
Vulnerability scanner is probably not taking into consideration that the issue has been patched and just say "you don't have 3.5.0 therefore you are open to this CVE".
I work at HPE
HPE Support Center offers support for your HPE services and products when and how you need it. Get started with HPE Support Center today.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-10-2023 11:45 PM
01-10-2023 11:45 PM
Re: HP MSA 2060 Vulnerability Assessment
Hi,
We would like to know if the information shared addressed your query.
Request you to please respond with a Yes/No
You may also click on "Accept as a Solution" button if the issue is resolved.
I work at HPE
HPE Support Center offers support for your HPE services and products when and how you need it. Get started with HPE Support Center today.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-02-2024 01:03 PM - last edited on 09-16-2024 02:19 AM by support_s
07-02-2024 01:03 PM - last edited on 09-16-2024 02:19 AM by support_s
Re: HP MSA 2060 Vulnerability Assessment
it same for CVE-2020-11022 and cve-2020-11023, IN210R004 is running on the same patch.
Nessus is reporting that th e version of JQuery hosted on the remote web server (web UI of the SAN) is greater than or equal to 1.2 and prior to 3.5.0. It is, therefore, affected by multiple cross site scripting vulnerabilities. Recommendation is to upgrade to version 3.5.0. Please refer to CVE-2020-11022 and CVE-2020-11023.
Can this be ignored or there is a workaround ?
- Tags:
- bios
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-10-2024 03:09 AM
07-10-2024 03:09 AM
Re: HP MSA 2060 Vulnerability Assessment
Hello @imranmohdkhan,
Thank you for writing to us.
You might want to consider creating a new topic by utilizing the "New Discussion" button, as this will not only enhance visibility compared to the old topic but also boost your chances of receiving responses from experts.
Thanks,
Sunitha G
I'm an HPE employee.
HPE Support Center offers support for your HPE services and products when and how you need it. Get started with HPE Support Center today.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]
