CVE-2019-6504

MEDIUM

Broadcom Automic Workload Automation 12.0-12.2 - Stored Cross-Site Scripting in Automic Web Interface

Title source: llm
STIX 2.1

Description

Insufficient output sanitization in the Automic Web Interface (AWI), in CA Automic Workload Automation 12.0 to 12.2, allow attackers to potentially conduct persistent cross site scripting (XSS) attacks via a crafted object.

Scores

CVSS v3 6.1
EPSS 0.0088
EPSS Percentile 75.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
broadcom/automic_workload_automation 12.0 - 12.2
Published Feb 06, 2019
Tracked Since Feb 18, 2026