CVE-2015-2344

MEDIUM

Vmware Vrealize Automation - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in VMware vRealize Automation 6.x before 6.2.4 on Linux allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

Scores

CVSS v3 5.4
EPSS 0.0010
EPSS Percentile 28.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Classification

CWE
CWE-79
Status draft

Affected Products (10)

vmware/vrealize_automation
vmware/vrealize_automation
vmware/vrealize_automation
vmware/vrealize_automation
vmware/vrealize_automation
vmware/vrealize_automation
vmware/vrealize_automation
vmware/vrealize_automation
vmware/vrealize_automation
vmware/vrealize_automation

Timeline

Published Mar 16, 2016
Tracked Since Feb 18, 2026