← Vulnerability feed

Vulnerability record · CVE-2014-2647 · published 19 October 2014

CVE-2014-2647: Hp operations agent cross-site scripting vulnerability

Hp · Operations Agent

Cross-site scripting (XSS) vulnerability in HP Operations Agent in HP Operations Manager (formerly OpenView Communications Broker) before 11.14 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

4.3 CVSS 2.0 Medium EPSS 3.4% · top 11.6% CWE-79 · Cross-site scripting
4.3CVSS 2.0 base score
3.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Cross-site scripting (XSS) vulnerability in HP Operations Agent in HP Operations Manager (formerly OpenView Communications Broker) before 11.14 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-2647 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2012-2019HP Operations Agent remote code execution flawHP Operations Agent before 11.03.12 contains an unspecified vulnerability that allows remote attackers to execute arbitrary code via unknown vectors,…EPSS 65%analysed10.0CVE-2012-2020HP Operations Agent remote code execution flawHP Operations Agent before 11.03.12 contains an unspecified vulnerability that lets remote attackers execute arbitrary code. The record gives no deta…EPSS 65%analysed10.0CVE-2010-0444Hp operations agent vulnerabilityHP Operations Agent 8.51, 8.52, 8.53, and 8.60 on Solaris 10 uses a blank password for the opc_op account, which allows remote attackers to execute a…EPSS 8.6%7.5CVE-2017-3733Openssl improper input validation vulnerabilityDuring a renegotiation handshake if the Encrypt-Then-Mac extension is negotiated where it was not in the original handshake (or vice-versa) then this…EPSS 13%7.5CVE-2010-3004Hp operations agent vulnerabilityUnspecified vulnerability in HP Operations Agent 7.36 and 8.6 on Windows allows remote attackers to execute arbitrary code via unknown vectors.EPSS 5.3%6.8CVE-2010-3005Hp operations agent vulnerabilityUnspecified vulnerability in HP Operations Agent 7.36 and 8.6 on Windows allows local users to gain privileges via unknown vectors.EPSS 0.28%6.4CVE-2011-2608Hp openview performance agent improper input validation vulnerabilityovbbccb.exe 6.20.50.0 and other versions in HP OpenView Performance Agent 4.70 and 5.0; and Operations Agent 11.0, 8.60.005, 8.60.006, 8.60.007, 8.60…EPSS 4.8%4.4CVE-2014-2630Hp operations agent vulnerabilityUnspecified vulnerability in HP Operations Agent 11.00, when Glance is used, allows local users to gain privileges via unknown vectors.EPSS 7.1%

Source: NIST National Vulnerability Database (record CVE-2014-2647), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.