CVE-2014-8247: XSS
Published Dec 16, 2014
·Updated
Cross-site scripting (XSS) vulnerability in CA Release Automation (formerly iTKO LISA Release Automation) before 4.7.1 b448 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
1 affected component
Broadcom Release Automation<=4.7.1
Event History
Dec 16, 2014
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-8247?
CVE-2014-8247 has a medium severity rating due to its potential for cross-site scripting attacks.
2
How can I fix CVE-2014-8247?
To mitigate CVE-2014-8247, upgrade CA Release Automation to version 4.7.1 or later.
3
What type of vulnerability is CVE-2014-8247?
CVE-2014-8247 is a cross-site scripting (XSS) vulnerability affecting CA Release Automation.
4
Who is affected by CVE-2014-8247?
CVE-2014-8247 affects users of CA Release Automation versions prior to 4.7.1 b448.
5
What can attackers do with CVE-2014-8247?
Attackers exploiting CVE-2014-8247 can inject arbitrary web scripts or HTML into the application.