CVE-2014-9224: XSS
Cross-site scripting (XSS) vulnerability in the ajaxswing webui in the Management Console server in the management server in Symantec Critical System Protection (SCSP) 5.2.9 through MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x through 6.0 MP1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9224?
CVE-2014-9224 has a medium severity rating due to its potential for Cross-site scripting (XSS) attacks.
How do I fix CVE-2014-9224?
To fix CVE-2014-9224, apply the latest patches or updates provided by Broadcom for Symantec Critical System Protection and Data Center Security.
Which versions are affected by CVE-2014-9224?
CVE-2014-9224 affects Symantec Critical System Protection 5.2.9 through MP6 and Symantec Data Center Security 6.0.x through 6.0 MP1.
Can CVE-2014-9224 be exploited remotely?
Yes, CVE-2014-9224 can be exploited remotely by authenticated users through the Management Console server.
What types of attacks can result from CVE-2014-9224?
CVE-2014-9224 can lead to Cross-site scripting (XSS) attacks, where malicious scripts are executed in the context of the user's browser.