First published: Wed Mar 09 2022(Updated: )
It was discovered that the /DsaDataTest endpoint is susceptible to Cross-site scripting (XSS) attack. It was noted that the Metric parameter does not have any input checks on the user input that allows an attacker to craft its own malicious payload to trigger a XSS vulnerability.
Credit: cve_disclosure@tech.gov.sg
Affected Software | Affected Version | How to fix |
---|---|---|
Riverbed Steelcentral Appinternals Dynamic Sampling Agent | >=11.0.0<11.8.8 | |
Riverbed Steelcentral Appinternals Dynamic Sampling Agent | >=12.0.0<12.13.0 | |
Riverbed Steelcentral Appinternals Dynamic Sampling Agent | =10.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-42856 is a vulnerability that allows an attacker to perform a Cross-site scripting (XSS) attack through the /DsaDataTest endpoint.
The severity of CVE-2021-42856 is medium (6.1).
Riverbed Steelcentral Appinternals Dynamic Sampling Agent versions 10.0.0 to 12.13.0 are affected by CVE-2021-42856.
An attacker can exploit CVE-2021-42856 by crafting a malicious payload in the Metric parameter of the /DsaDataTest endpoint to trigger a Cross-site scripting (XSS) vulnerability.
There is currently no known fix for CVE-2021-42856. It is recommended to follow the vendor's security advisories and apply any patches or updates as they become available.