PT-2015-7533 · Ca Technologies+2 · Ca Release Automation+2
Sergey Markov
·
Published
2015-10-14
·
Updated
2018-10-09
·
CVE-2015-7370
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Open Flash Chart 2
Revive Adserver versions prior to 3.2.2
CA Release Automation versions prior to 5.0.2-227
CA Release Automation versions prior to 5.5.1-1616
CA Release Automation versions prior to 5.5.2-434
CA Release Automation versions prior to 6.1.0-1026
Description
The issue allows remote attackers to inject arbitrary web script or HTML via the
id or data-file parameter, potentially leading to cross-site scripting (XSS) attacks.Recommendations
For Open Flash Chart 2, update to a version that is not affected by this issue.
For Revive Adserver versions prior to 3.2.2, update to version 3.2.2 or later.
For CA Release Automation versions prior to 5.0.2-227, update to version 5.0.2-227 or later.
For CA Release Automation versions prior to 5.5.1-1616, update to version 5.5.1-1616 or later.
For CA Release Automation versions prior to 5.5.2-434, update to version 5.5.2-434 or later.
For CA Release Automation versions prior to 6.1.0-1026, update to version 6.1.0-1026 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ca Release Automation
Open Flash Chart 2
Revive Adserver