First published: Thu Sep 11 2014(Updated: )
Cross-site scripting (XSS) vulnerability in the JobScheduler Operations Center (JOC) in SOS JobScheduler before 1.6.4246 and 1.7.x before 1.7.4241 allows remote attackers to inject arbitrary web script or HTML via the hash property (location.hash).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Operation Scheduler | <=1.6.4131 | |
Siemens Operation Scheduler | =1.6.4014 | |
Siemens Operation Scheduler | =1.6.4043 | |
Siemens Operation Scheduler | =1.7.4177 | |
Siemens Operation Scheduler | =1.7.4189 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-5391 is classified as a medium severity cross-site scripting vulnerability.
To resolve CVE-2014-5391, upgrade your SOS JobScheduler to version 1.6.4246 or higher, or 1.7.4241 or higher.
CVE-2014-5391 affects SOS JobScheduler versions prior to 1.6.4246 and 1.7.x before 1.7.4241.
Yes, CVE-2014-5391 allows remote attackers to inject arbitrary web scripts or HTML into the application.
CVE-2014-5391 exploits the hash property (location.hash) to perform cross-site scripting attacks.