CVE-2015-0513: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the administrative user interface in EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 allow remote authenticated users to inject arbitrary web script or HTML by leveraging privileged access to set crafted values of unspecified fields.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0513?
CVE-2015-0513 is classified as a moderate severity vulnerability primarily due to the potential for cross-site scripting (XSS) attacks.
How do I fix CVE-2015-0513?
To fix CVE-2015-0513, upgrade EMC M&R (Watch4Net) to version 6.5u1 or later, and Dell EMC ViPR SRM to version 3.6.1 or later.
Who is affected by CVE-2015-0513?
CVE-2015-0513 affects users of EMC Watch4Net versions up to 6.5 and Dell EMC ViPR SRM versions up to 3.6.0.
What type of vulnerability is CVE-2015-0513?
CVE-2015-0513 is a cross-site scripting (XSS) vulnerability that allows remote authenticated users to inject arbitrary web scripts or HTML.
What should I do if I can't upgrade to fix CVE-2015-0513?
If unable to upgrade to fix CVE-2015-0513, minimize access privileges for administrative users to limit potential exploitation.