First published: Mon Jul 29 2019(Updated: )
An issue was discovered in Veritas Resiliency Platform (VRP) before 3.4 HF1. A persistent cross-site scripting (XSS) vulnerability allows a malicious VRP user to inject malicious script into another user's browser, related to resiliency plans functionality. A victim must open a resiliency plan that an attacker has access to.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Veritas Resiliency Platform | <3.3.2 | |
Veritas Resiliency Platform | =3.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-14415 is classified as a medium severity vulnerability due to its ability to exploit cross-site scripting (XSS) within Veritas Resiliency Platform.
To mitigate CVE-2019-14415, users should upgrade Veritas Resiliency Platform to version 3.4 HF1 or later.
CVE-2019-14415 affects users of Veritas Resiliency Platform versions prior to 3.4 HF1, specifically those using version 3.3.2 or lower.
CVE-2019-14415 is a persistent cross-site scripting (XSS) vulnerability that allows script injection into other users' browsers.
An attacker exploiting CVE-2019-14415 can inject malicious scripts into a victim's browser when they open a resiliency plan.