Medium severity6.1NVD Advisory· Published May 2, 2019· Updated Jun 17, 2026
CVE-2019-3490
CVE-2019-3490
Description
A DOM based XSS vulnerability has been identified in the Netstorage component of Open Enterprise Server (OES) allowing a remote attacker to execute javascript in the victims browser by tricking the victim into clicking on a specially crafted link. This affects OES versions OES2015SP1, OES2018, and OES2018SP1. Older versions may be affected but were not tested as they are out of support.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6cpe:2.3:a:microfocus:open_enterprise_server:2015.1:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:microfocus:open_enterprise_server:2015.1:*:*:*:*:*:*:*
- cpe:2.3:a:microfocus:open_enterprise_server:2018.0:*:*:*:*:*:*:*
- cpe:2.3:a:microfocus:open_enterprise_server:2018.1:*:*:*:*:*:*:*
- (no CPE)
- OES/Netstorage component of Open Enterprise Serverv5Range: OES2015SP1
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.