PT-2024-32853 · Veritas · Veritas Data Insight
Published
2024-10-03
·
Updated
2025-10-17
·
CVE-2024-47854
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Veritas Data Insight versions prior to 7.1
Description
A security issue was discovered that allows a remote attacker to inject an arbitrary web script into an HTTP request, which could reflect back to an authenticated user without sanitization if executed by that user. This issue affects Veritas Data Insight and could potentially lead to data theft or malicious code execution.
Recommendations
For versions prior to 7.1, upgrade the affected component to version 7.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the HTTP request handler to minimize the risk of exploitation.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Veritas Data Insight