First published: Wed Feb 06 2019(Updated: )
Insufficient output sanitization in the Automic Web Interface (AWI), in CA Automic Workload Automation 12.0 to 12.2, allow attackers to potentially conduct persistent cross site scripting (XSS) attacks via a crafted object.
Credit: vuln@ca.com vuln@ca.com
Affected Software | Affected Version | How to fix |
---|---|---|
Broadcom CA Automic Workload Automation | >=12.0<=12.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-6504 has a medium severity rating due to the potential for persistent XSS attacks.
To fix CVE-2019-6504, ensure you upgrade to a later version of CA Automic Workload Automation beyond 12.2.
CVE-2019-6504 affects versions 12.0 to 12.2 of CA Automic Workload Automation.
CVE-2019-6504 allows for persistent cross site scripting (XSS) attacks due to insufficient output sanitization.
The vendor for the affected product is Broadcom.