← Vulnerability feed

Vulnerability record · CVE-2011-0274 · published 24 January 2011

CVE-2011-0274: Hp business availability center cross-site scripting vulnerability

Hp · Business Availability Center

Cross-site scripting (XSS) vulnerability in HP Business Availability Center (BAC) 7.x through 7.55 and 8.x through 8.05, and Business Service Management (BSM) through 9.01, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

4.3 CVSS 2.0 Medium EPSS 2.1% · top 19.3% CWE-79 · Cross-site scripting
4.3CVSS 2.0 base score
2.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
14References
16 Jun 2026Last modified by NVD

Description

Cross-site scripting (XSS) vulnerability in HP Business Availability Center (BAC) 7.x through 7.55 and 8.x through 8.05, and Business Service Management (BSM) through 9.01, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2011-0274 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2012-2561Hp business service management permissions and access controls vulnerabilityHP Business Service Management (BSM) 9.12 does not properly restrict the uploading of .war files, which allows remote attackers to execute arbitrary …EPSS 8.6%8.8CVE-2016-4405Hp business service management deserialization of untrusted data vulnerabilityA remote code execution vulnerability was identified in HP Business Service Management (BSM) using Apache Commons Collection Java Deserialization ver…EPSS 4.8%6.8CVE-2012-3256Hp business availability center cross-site request forgery vulnerabilityCross-site request forgery (CSRF) vulnerability in HP Business Availability Center (BAC) 8.07 allows remote attackers to hijack the authentication of…EPSS 0.97%5.4CVE-2016-4392Hp business service management cross-site scripting vulnerabilityA remote cross site scripting vulnerability has been identified in HP Business Service Management software v9.1x, v9.20 - v9.25IP1.EPSS 1.1%5.0CVE-2015-3269Hp business service management information exposure vulnerabilityApache Flex BlazeDS, as used in flex-messaging-core.jar in Adobe LiveCycle Data Services (LCDS) 3.0.x before 3.0.0.354170, 4.5 before 4.5.1.354169, 4…EPSS 9.8%4.6CVE-2012-3257Hp business availability center vulnerabilityHP Business Availability Center (BAC) 8.07 allows remote authenticated users to hijack web sessions via unspecified vectors.EPSS 1.1%4.3CVE-2012-3255Hp business availability center cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in HP Business Availability Center (BAC) 8.07 allows remote attackers to inject arbitrary web script or HTML…EPSS 1.6%4.3CVE-2012-0132Hp business availability center cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in HP Business Availability Center (BAC) 9.01 allows remote attackers to inject arbitrary web script or HTML…EPSS 1.9%

Source: NIST National Vulnerability Database (record CVE-2011-0274), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.