CVE-2019-6504 Vulnerability Details

  /     /     /  

CVE-2019-6504 Metadata Quick Info

CVE Published: 06/02/2019 | CVE Updated: 16/09/2024 | CVE Year: 2019
Source: ca | Vendor: CA Technologies - A Broadcom Company | Product: CA Automic Workload Automation
Status : PUBLISHED

CVE-2019-6504 Description

Insufficient output sanitization in the Automic Web Interface (AWI), in CA Automic Workload Automation 12.0 to 12.2, allow attackers to potentially conduct persistent cross site scripting (XSS) attacks via a crafted object.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: Persistent Cross Site Scripting
Source: CA Technologies - A Broadcom Company

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).