PT-2014-2180 · Imperva · Imperva Securesphere Web Application Firewall

Published

2014-09-11

·

Updated

2017-08-29

·

CVE-2011-4887

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Imperva SecureSphere Web Application Firewall (WAF) version 9.0
Description A cross-site scripting (XSS) issue exists in the Violations Table of the management GUI in the MX Management Server, allowing remote attackers to inject arbitrary web script or HTML via the username field.
Recommendations For version 9.0, consider restricting access to the management GUI to minimize the risk of exploitation until a fix is available. Avoid using the username field in the Violations Table until the issue is resolved.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-4887

Affected Products

Imperva Securesphere Web Application Firewall