CVE-2017-7421: Micro Focus Directory Server

Medium severity, CVSS 6.1. EPSS: 1.3% chance of exploitation in the next 30 days.

Reflected and stored Cross-Site Scripting (XSS, CWE-79) vulnerabilities in Directory Server (aka Enterprise Server Administration web UI) and ESMAC (aka Enterprise Server Monitor and Control) in Micro Focus Enterprise Developer and Enterprise Server 2.3 and earlier, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allow remote authenticated attackers to bypass protection mechanisms (CWE-693) and other security features.

Affected products

  • Micro Focus Directory Server: affected versions not specified
  • Micro Focus Enterprise Developer: version 2.3 only
  • Micro Focus Enterprise Server: up to and including 2.3; version 2.3 only
  • Micro Focus Enterprise Server Monitor And Control: affected versions not specified

Published 2017-08-21. Last modified 2026-06-17.