CVE-2015-6549: XSS
Published Oct 3, 2015
·Updated
Cross-site scripting (XSS) vulnerability in an application console in the server in Symantec NetBackup OpsCenter before 7.7.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
1 affected component
Symantec NetBackup OpsCenter<=7.7.0
Event History
Oct 3, 2015
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-6549?
CVE-2015-6549 is classified as a medium severity vulnerability due to the potential for cross-site scripting attacks.
2
How do I fix CVE-2015-6549?
To fix CVE-2015-6549, upgrade Symantec NetBackup OpsCenter to version 7.7.1 or later.
3
Who is affected by CVE-2015-6549?
CVE-2015-6549 affects users of Symantec NetBackup OpsCenter versions prior to 7.7.1.
4
What type of vulnerability is CVE-2015-6549?
CVE-2015-6549 is a cross-site scripting (XSS) vulnerability that allows injection of arbitrary web scripts or HTML.
5
Can CVE-2015-6549 be exploited remotely?
Yes, CVE-2015-6549 can be exploited remotely by authenticated users.