First published: Tue Feb 28 2023(Updated: )
Active IQ Unified Manager for VMware vSphere, Linux, and Microsoft Windows versions prior to 9.11P1 are susceptible to a vulnerability which allows administrative users to perform a Stored Cross-Site Scripting (XSS) attack.
Credit: security-alert@netapp.com
Affected Software | Affected Version | How to fix |
---|---|---|
Netapp Active Iq Unified Manager Linux | <9.11p1 | |
Netapp Active Iq Unified Manager Vmware Vsphere | <9.11p1 | |
Netapp Active Iq Unified Manager Windows | <9.11p1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2022-23239.
The severity of CVE-2022-23239 is medium (4.8).
The affected software for CVE-2022-23239 is Netapp Active Iq Unified Manager version up to 9.11p1 on Linux, VMware vSphere, and Windows.
CVE-2022-23239 is a vulnerability in Active IQ Unified Manager for VMware vSphere, Linux, and Microsoft Windows versions prior to 9.11P1, allowing administrative users to perform a Stored Cross-Site Scripting (XSS) attack.
To fix CVE-2022-23239, users should update Active IQ Unified Manager to version 9.11P1 or later.