4.8
CVSSv3

CVE-2019-14415

Published: 29/07/2019 Updated: 03/03/2023
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 4.8 | Impact Score: 2.7 | Exploitability Score: 1.7
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

An issue exists in Veritas Resiliency Platform (VRP) prior to 3.4 HF1. A persistent cross-site scripting (XSS) vulnerability allows a malicious VRP user to inject malicious script into another user's browser, related to resiliency plans functionality. A victim must open a resiliency plan that an attacker has access to.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

veritas resiliency platform

veritas resiliency platform 3.3.2

Mailing Lists

Four vulnerabilities have been fixed in VRP 34 HF1, one of which is of critical severity Directory traversal vulnerability related to uploading application bundles CVE-2019-14415 Critical severity Arbitrary command execution vulnerability with root privilege related to DNS server configuration CVE-2019-14416 High severity Arbitrary command exe ...