First published: Fri Mar 04 2022(Updated: )
An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2 Patch 600 and 8.x before 8.0.0 Patch 100. A reflected cross-site scripting (XSS) vulnerability in admin/cgi-bin/listdir.pl allows authenticated remote administrators to inject arbitrary web script or HTML into an HTTP GET parameter (which reflect the user input without sanitization).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Veritas InfoScale Operations Manager | <7.4.2.600 | |
Veritas InfoScale Operations Manager | =8.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-26483 is a reflected cross-site scripting (XSS) vulnerability in Veritas InfoScale Operations Manager (VIOM) before 7.4.2 Patch 600 and 8.x before 8.0.0 Patch 100.
CVE-2022-26483 allows authenticated remote administrators to inject arbitrary web script or HTML into an HTT.
Veritas InfoScale Operations Manager before 7.4.2 Patch 600 and 8.x before 8.0.0 Patch 100 are affected by CVE-2022-26483.
CVE-2022-26483 has a severity rating of 4.8 (medium).
Updating to version 7.4.2 Patch 600 or version 8.0.0 Patch 100 resolves CVE-2022-26483 in Veritas InfoScale Operations Manager.