← Zuruck zu CVEs
CVE-2019-6504
N/ABeschreibung
Insufficient output sanitization in the Automic Web Interface (AWI), in CA Automic Workload Automation 12.0 to 12.2, allow attackers to potentially conduct persistent cross site scripting (XSS) attacks via a crafted object.
CVE Details
CVSS v3.1 BewertungN/A
Veroffentlicht2/6/2019
Zuletzt geandert11/21/2024
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
broadcom:automic_workload_automation
Schwachen (CWE)
CWE-79
Referenzen
http://www.securityfocus.com/bid/106755(vuln@ca.com)
https://marc.info/?l=bugtraq&m=154874504200510&w=2(vuln@ca.com)
https://packetstormsecurity.com/files/151325/CA-Automic-Workload-Automation-12.x-Cross-Site-Scripting.html(vuln@ca.com)
https://seclists.org/fulldisclosure/2019/Jan/61(vuln@ca.com)
http://www.securityfocus.com/bid/106755(af854a3a-2127-422b-91ae-364da2661108)
https://communities.ca.com/community/product-vulnerability-response/blog/2019/01/24/ca20190124-01-security-notice-for-ca-automic-workload-automation(af854a3a-2127-422b-91ae-364da2661108)
https://marc.info/?l=bugtraq&m=154874504200510&w=2(af854a3a-2127-422b-91ae-364da2661108)
https://packetstormsecurity.com/files/151325/CA-Automic-Workload-Automation-12.x-Cross-Site-Scripting.html(af854a3a-2127-422b-91ae-364da2661108)
https://sec-consult.com/en/blog/advisories/cross-site-scripting-in-ca-automic-workload-automation-web-interface-formerly-automic-automation-engine/(af854a3a-2127-422b-91ae-364da2661108)
https://seclists.org/fulldisclosure/2019/Jan/61(af854a3a-2127-422b-91ae-364da2661108)
https://support.ca.com/us/product-content/recommended-reading/security-notices/CA20190124-01-security-notice-for-ca-automic-workload-automation.html(af854a3a-2127-422b-91ae-364da2661108)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.