CVE-2011-1863 describes a script injection vulnerability affecting HP Service Manager versions 7.02, 7.11, 9.20, and 9.21, as well as HP Service Center 6.2.8. This vulnerability allows remote authenticated users to execute arbitrary scripts through unspecified vectors. With a CVSS score of 7.5, it poses a significant risk, potentially leading to complete compromise of confidentiality, partial integrity, and partial availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or widespread community discussion beyond a single mention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.2.8CPE matchmatch criteria | cpe:2.3:a:hp:service_center:6.2.8:*:*:*:*:*:*:* | ||
7.02CPE matchmatch criteria | cpe:2.3:a:hp:service_manager:7.02:*:*:*:*:*:*:* | ||
7.11CPE matchmatch criteria | cpe:2.3:a:hp:service_manager:7.11:*:*:*:*:*:*:* | ||
9.20CPE matchmatch criteria | cpe:2.3:a:hp:service_manager:9.20:*:*:*:*:*:*:* | ||
9.21CPE matchmatch criteria | cpe:2.3:a:hp:service_manager:9.21:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:S/C:C/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.