First published: Thu May 02 2019(Updated: )
A DOM based XSS vulnerability has been identified in the Netstorage component of Open Enterprise Server (OES) allowing a remote attacker to execute javascript in the victims browser by tricking the victim into clicking on a specially crafted link. This affects OES versions OES2015SP1, OES2018, and OES2018SP1. Older versions may be affected but were not tested as they are out of support.
Credit: security@microfocus.com security@opentext.com
Affected Software | Affected Version | How to fix |
---|---|---|
Novell Open Enterprise Server | =2015.1 | |
Novell Open Enterprise Server | =2018.0 | |
Novell Open Enterprise Server | =2018.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-3490 is classified as a medium severity vulnerability.
To fix CVE-2019-3490, apply the recommended updates from Micro Focus for affected versions of Open Enterprise Server.
CVE-2019-3490 allows remote attackers to execute arbitrary JavaScript in the victim's browser, which can lead to session hijacking or unauthorized actions.
CVE-2019-3490 affects Open Enterprise Server versions 2015 SP1 and 2018 SP1.
Yes, CVE-2019-3490 is identified as a DOM-based cross-site scripting (XSS) vulnerability.