MSA Storage
1819523 Members
3041 Online
109603 Solutions
New Discussion

HP MSA 2060 Vulnerability Assessment

 
SOLVED
Go to solution
OM4
Member

HP MSA 2060 Vulnerability Assessment

Hi Admin

We have one "Vulnerability Assessment Report" about HP MSA 2060 at controller A,  controller B
JQuery 1.2 < 3.5.0 Multiple XSS
I didn't find any setting about web, How can I check ?

OMunoz
3 REPLIES 3
JSH-MSA
HPE Pro

Re: HP MSA 2060 Vulnerability Assessment

I assume this is for CVE-2020-11022 based on the JQuery versions listed. The MSA 1060/2060/2062 is not vulnerable because the array does not pass html containing <option> elements from untrusted sources to jQuery's DOM manipulation methods.

I work at HPE
HPE Support Center offers support for your HPE services and products when and how you need it. Get started with HPE Support Center today.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]
ArunKKR
HPE Pro

Re: HP MSA 2060 Vulnerability Assessment

Hi,

 

From MSA n-2 firmware version IN110R001 release notes:

 

The following enhancements have been added in the IN110R001 release:
Applied patches to mitigate CVE-2020-11022 and CVE-2020-11023.

 

Release notes download link:

 

https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=a00116234en_us



I work at HPE
HPE Support Center offers support for your HPE services and products when and how you need it. Get started with HPE Support Center today.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]
Accept or Kudo
Sunitha_Mod
Moderator
Solution

Re: HP MSA 2060 Vulnerability Assessment

Hello @OM4,

Let us know if you were able to resolve the issue.

If you have no further query and you are satisfied with the answer then kindly mark the topic as Solved so that it is helpful for all community members.



Thanks,
Sunitha G
I'm an HPE employee.
HPE Support Center offers support for your HPE services and products when and how you need it. Get started with HPE Support Center today.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]
Accept or Kudo