First published: Tue Mar 07 2017(Updated: )
Cross-site scripting (XSS) vulnerability in CA Service Desk Manager (formerly CA Service Desk) 12.9 and 14.1 allows remote attackers to inject arbitrary web script or HTML via the QBE.EQ.REF_NUM parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Broadcom Service Desk Manager | =12.9 | |
Broadcom Service Desk Manager | =14.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-9148 is classified as a medium severity vulnerability due to its potential impact on sensitive information via cross-site scripting.
To fix CVE-2016-9148, upgrade to a non-vulnerable version of CA Service Desk Manager, specifically versions after 14.1.
CVE-2016-9148 facilitates cross-site scripting (XSS) attacks which allow remote attackers to inject malicious scripts.
CVE-2016-9148 affects CA Service Desk Manager versions 12.9 and 14.1.
You can determine if your system is vulnerable to CVE-2016-9148 by checking if it is running CA Service Desk Manager version 12.9 or 14.1.