Database/Firmware, BMC & network fabric
Supermicro BMC (IPMI web interface, XSS via IE11): Injection that fires specifically through Internet Explorer 11
Impact
Injection that fires specifically through Internet Explorer 11. Worth keeping on the list precisely because BMC web UIs are the last place in a datacenter where an ancient browser is still in the loop - legacy Java KVM clients and jump hosts frozen on old images keep IE alive long after everything else moved on.
Who can reach it
An operator administering the BMC from IE11 on Windows, with network reach to the BMC.
What to do
BMC firmware flash per board. The cheaper immediate action is retiring IE11 from your management jump hosts entirely, which also kills a class of legacy KVM client exposure at the same time.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.