PT-2019-13684 · Veritas · Veritas Resiliency Platform
Published
2019-07-29
·
Updated
2023-03-03
·
CVE-2019-14415
CVSS v3.1
5.9
Medium
| Vector | AC:L/AV:N/A:L/C:L/I:L/PR:H/S:C/UI:R |
Name of the Vulnerable Software and Affected Versions
Veritas Resiliency Platform versions prior to 3.4 HF1
Description
A persistent cross-site scripting issue allows a malicious user to inject malicious script into another user's browser, related to resiliency plans functionality. This occurs when a victim opens a resiliency plan that an attacker has access to.
Recommendations
For versions prior to 3.4 HF1, update to version 3.4 HF1 or later to resolve the issue. As a temporary workaround, consider restricting access to resiliency plans to minimize the risk of exploitation.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Veritas Resiliency Platform