A DOM based XSS vulnerability has been identified in the Netstorage component of Open Enterprise Server (OES) allowing a remote attacker to execute javascript in the victims browser by tricking the victim into clicking on a specially crafted link. This affects OES versions OES2015SP1, OES2018, and OES2018SP1. Older versions may be affected but were not tested as they are out of support.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-13128 | A DOM based XSS vulnerability has been identified in the Netstorage component of Open Enterprise Server (OES) allowing a remote attacker to execute javascript in the victims browser by tricking the victim into clicking on a specially crafted link. This affects OES versions OES2015SP1, OES2018, and OES2018SP1. Older versions may be affected but were not tested as they are out of support. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://support.microfocus.com/kb/doc.php?id=7023828 |
|
History
No history.
Status: PUBLISHED
Assigner: microfocus
Published:
Updated: 2024-08-04T19:12:09.334Z
Reserved: 2018-12-31T00:00:00.000Z
Link: CVE-2019-3490
No data.
Status : Modified
Published: 2019-05-02T17:29:02.787
Modified: 2024-11-21T04:42:07.950
Link: CVE-2019-3490
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD