CVE-2015-2420: XSS
Cross-site scripting (XSS) vulnerability in Microsoft System Center 2012 Operations Manager Gold before Rollup 8, SP1 before Rollup 10, and R2 before Rollup 7 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "System Center Operations Manager Web Console XSS Vulnerability."
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2420?
CVE-2015-2420 has a Common Vulnerability Scoring System (CVSS) score indicating a medium severity level.
How do I fix CVE-2015-2420?
To fix CVE-2015-2420, apply the latest rollup update for your version of Microsoft System Center 2012 Operations Manager.
What type of vulnerability is CVE-2015-2420?
CVE-2015-2420 is classified as a cross-site scripting (XSS) vulnerability.
What software versions are affected by CVE-2015-2420?
CVE-2015-2420 affects various versions of Microsoft System Center 2012 Operations Manager prior to specific rollups.
Can CVE-2015-2420 be exploited remotely?
Yes, CVE-2015-2420 can be exploited remotely by attackers through a crafted URL.