CVE-2015-2827
CA Spectrum 9.2.x-9.3.x - Authenticated Cross-Site Scripting
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in CA Spectrum 9.2.x and 9.3.x before 9.3 H02 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
References (4)
Core 4
Core References
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/535205/100/0/threaded
Vendor Advisory x_refsource_confirm
http://www.ca.com/us/support/ca-support-online/product-content/recommended-reading/security-notices/ca20150407-01-security-notice-for-ca-spectrum.aspx
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/73963
Exploit, Third Party Advisory x_refsource_misc
http://packetstormsecurity.com/files/131330/Security-Notice-For-CA-Spectrum.html
Scores
EPSS
0.0022
EPSS Percentile
44.5%
Details
CWE
CWE-79
Status
published
Products (2)
broadcom/spectrum
9.2
broadcom/spectrum
9.3
Published
Apr 08, 2015
Tracked Since
Feb 18, 2026