Podatność w OpenText Vertica polegająca na nieprawidłowym neutralizowaniu danych wejściowych podczas generowania strony internetowej pozwala na ataki Reflected XSS. Luka umożliwia atak Reflected XSS w aplikacji konsoli zarządzania Vertica i dotyczy wersji 10.0–10.X, 11.0–11.X, 12.0–12.X, 23.0–23.X, 24.0–24.X, 25.1.0–25.1.X, 25.2.0–25.2.X i 25.3.0–25.3.X.
▸ Pokaż oryginał (EN)
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText™ Vertica allows Reflected XSS. The vulnerability could lead to Reflected XSS attack of cross-site scripting in Vertica management console application.This issue affects Vertica: from 10.0 through 10.X, from 11.0 through 11.X, from 12.0 through 12.X, from 23.0 through 23.X, from 24.0 through 24.X, from 25.1.0 through 25.1.X, from 25.2.0 through 25.2.X, from 25.3.0 through 25.3.X.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:X/RE:X/U:XOpentext Vertica
APPOpentext10.0.0-0 – 25.4.0-0 (bez)
Powiązane podatności
Zdalne przejęcie uprawnień w HPE Vertica Analytics Platform
Command injection w HPE Vertica Analytics Management Console (mcPort)
The vertica-udx-zygote process in HP Vertica 7.1.1 UDx does not require authentication, which allows remote at...
Podatność typu observable response discrepancy w OpenText Vertica umożliwia atak typu Password Brute Forcing. ...
Nieprawidłowa neutralizacja danych wejściowych podczas generowania strony internetowej (cross-site scripting) ...