First published: Tue Nov 26 2019(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webclient of Siemens AG Polarion could allow an attacker to exploit a reflected XSS vulnerability. This issue affects: Siemens AG Polarion All versions < 19.2.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Polarion ALM | <19.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-13935 is an improper neutralization of input during web page generation (cross-site scripting) vulnerability in Siemens AG Polarion.
CVE-2019-13935 affects all versions of Siemens AG Polarion prior to 19.2.
CVE-2019-13935 has a severity rating of medium (5.4).
An attacker can exploit CVE-2019-13935 by leveraging a reflected XSS vulnerability in the web client of Siemens AG Polarion.
Yes, users should update to Siemens AG Polarion version 19.2 or later to fix CVE-2019-13935.