VYPR
Medium severity6.1NVD Advisory· Published May 2, 2019· Updated Jun 17, 2026

CVE-2019-3490

CVE-2019-3490

Description

A DOM based XSS vulnerability has been identified in the Netstorage component of Open Enterprise Server (OES) allowing a remote attacker to execute javascript in the victims browser by tricking the victim into clicking on a specially crafted link. This affects OES versions OES2015SP1, OES2018, and OES2018SP1. Older versions may be affected but were not tested as they are out of support.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

6
  • cpe:2.3:a:microfocus:open_enterprise_server:2015.1:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:microfocus:open_enterprise_server:2015.1:*:*:*:*:*:*:*
    • cpe:2.3:a:microfocus:open_enterprise_server:2018.0:*:*:*:*:*:*:*
    • cpe:2.3:a:microfocus:open_enterprise_server:2018.1:*:*:*:*:*:*:*
    • (no CPE)
  • OES/Netstorage component of Open Enterprise Serverv5
    Range: OES2015SP1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.