CVE-2019-14415: XSS
An issue was discovered in Veritas Resiliency Platform (VRP) before 3.4 HF1. A persistent cross-site scripting (XSS) vulnerability allows a malicious VRP user to inject malicious script into another user's browser, related to resiliency plans functionality. A victim must open a resiliency plan that an attacker has access to.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-14415?
CVE-2019-14415 is classified as a medium severity vulnerability due to its ability to exploit cross-site scripting (XSS) within Veritas Resiliency Platform.
How do I fix CVE-2019-14415?
To mitigate CVE-2019-14415, users should upgrade Veritas Resiliency Platform to version 3.4 HF1 or later.
Who is affected by CVE-2019-14415?
CVE-2019-14415 affects users of Veritas Resiliency Platform versions prior to 3.4 HF1, specifically those using version 3.3.2 or lower.
What type of vulnerability is CVE-2019-14415?
CVE-2019-14415 is a persistent cross-site scripting (XSS) vulnerability that allows script injection into other users' browsers.
What can an attacker do with CVE-2019-14415?
An attacker exploiting CVE-2019-14415 can inject malicious scripts into a victim's browser when they open a resiliency plan.