Document Title: HPESBST03859 rev.1 - HPE XP P9000 Command View Advanced Edition Software (CVAE) - Multiple Vulnerabilities Document Type: Security Bulletin Potential Security Impact: - Local: Cross-Site Scripting (XSS), URL Redirection - Remote: Cross-Site Scripting (XSS), URL Redirection Software Affected: HPE XP P9000 Command View Advanced Edition Software (CVAE) versions 7.0.0-00 to earlier than 8.60-00 CVEs: - CVE-2018-7090: XSS - CVE-2018-7091: Open Redirect Resolution: - Install fixed versions: - DevMgr 8.60-00 - RepMgr 8.60-00 - TSMgr is corrected by upgrading DevMgr. Severity: Medium CVSS Scores: - CVE-2018-7090: - V3 Base Score: 5.9 - V2 Base Score: 4.3 - CVE-2018-7091: - V3 Base Score: 4.0 - V2 Base Score: 4.0