First published: Wed Dec 09 2009(Updated: )
Cross-site scripting (XSS) vulnerability in the web interface in CA Service Desk 12.1 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Broadcom CA Service Catalog | =12.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-4149 is considered a medium severity vulnerability due to its potential for exploitation through cross-site scripting.
To fix CVE-2009-4149, upgrade CA Service Desk to a version where the XSS vulnerability is patched.
CVE-2009-4149 can be exploited to perform cross-site scripting attacks, allowing attackers to inject malicious scripts into web pages.
CVE-2009-4149 affects CA Service Desk version 12.1.
Organizations using CA Service Desk 12.1 without the necessary patches are vulnerable to CVE-2009-4149.