First published: Wed Jan 21 2015(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in the administrative user interface in EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 allow remote authenticated users to inject arbitrary web script or HTML by leveraging privileged access to set crafted values of unspecified fields.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
EMC Watch4Net | <=6.5 | |
Dell EMC ViPR SRM | <=3.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0513 is classified as a moderate severity vulnerability primarily due to the potential for cross-site scripting (XSS) attacks.
To fix CVE-2015-0513, upgrade EMC M&R (Watch4Net) to version 6.5u1 or later, and Dell EMC ViPR SRM to version 3.6.1 or later.
CVE-2015-0513 affects users of EMC Watch4Net versions up to 6.5 and Dell EMC ViPR SRM versions up to 3.6.0.
CVE-2015-0513 is a cross-site scripting (XSS) vulnerability that allows remote authenticated users to inject arbitrary web scripts or HTML.
If unable to upgrade to fix CVE-2015-0513, minimize access privileges for administrative users to limit potential exploitation.