CVE-2019-3490: Micro Focus Open Enterprise Server

Medium severity, CVSS 6.1. EPSS: 1% chance of exploitation in the next 30 days.

A DOM based XSS vulnerability has been identified in the Netstorage component of Open Enterprise Server (OES) allowing a remote attacker to execute javascript in the victims browser by tricking the victim into clicking on a specially crafted link. This affects OES versions OES2015SP1, OES2018, and OES2018SP1. Older versions may be affected but were not tested as they are out of support.

Affected products

  • Micro Focus Open Enterprise Server: version 2015.1 only; version 2018.0 only; version 2018.1 only

Published 2019-05-02. Last modified 2026-06-17.