First published: Mon Jul 15 2024(Updated: )
A reflected cross-site scripting (XSS) vulnerability exists in the PAM UI web interface. A remote attacker able to convince a PAM user to click on a specially crafted link to the PAM UI web interface could potentially execute arbitrary client-side code in the context of PAM UI.
Credit: secure@symantec.com
Affected Software | Affected Version | How to fix |
---|---|---|
Broadcom Symantec Privileged Access Management | >=4.1.0<=4.1.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-38493 has a moderate severity rating due to its potential for exploiting reflected cross-site scripting in the PAM UI.
To mitigate CVE-2024-38493, users should update to a secure version of the Broadcom Symantec Privileged Access Management software beyond version 4.1.7.
CVE-2024-38493 affects users of Broadcom Symantec Privileged Access Management versions between 4.1.0 and 4.1.7.
CVE-2024-38493 is a reflected cross-site scripting (XSS) vulnerability that allows for potential execution of arbitrary client-side code.
Yes, CVE-2024-38493 can be exploited remotely if an attacker convinces a user to click a specially crafted link.