VYPR
Medium severity5.4NVD Advisory· Published Jan 10, 2020· Updated Jun 17, 2026

CVE-2019-18588

CVE-2019-18588

Description

Dell EMC Unisphere for PowerMax versions prior to 9.1.0.9, Dell EMC Unisphere for PowerMax versions prior to 9.0.2.16, and Dell EMC PowerMax OS 5978.221.221 and 5978.479.479 contain a Cross-Site Scripting (XSS) vulnerability. An authenticated malicious user may potentially exploit this vulnerability to inject javascript code and affect other authenticated users' sessions.

Affected products

6
  • Dell/Unisphere For Powermaxllm-fuzzy2 versions
    <9.1.0.9, <9.0.2.16+ 1 more
    • (no CPE)range: <9.1.0.9, <9.0.2.16
    • (no CPE)range: unspecified
  • Dell/PowerMaxllm-fuzzy
    Range: 5978.221.221, 5978.479.479
  • Dell/Emc Powermax2 versions
    cpe:2.3:a:dell:emc_powermax:5978.221.221:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:dell:emc_powermax:5978.221.221:*:*:*:*:*:*:*
    • cpe:2.3:a:dell:emc_powermax:5978.479.479:*:*:*:*:*:*:*
  • cpe:2.3:a:dell:emc_unisphere_for_powermax:*:*:*:*:*:*:*:*
    Range: <9.0.2.16

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.