VYPR
High severity7.2NVD Advisory· Published Mar 7, 2019· Updated Jun 17, 2026

CVE-2019-3776

CVE-2019-3776

Description

Pivotal Operations Manager, 2.1.x versions prior to 2.1.20, 2.2.x versions prior to 2.2.16, 2.3.x versions prior to 2.3.10, 2.4.x versions prior to 2.4.3, contains a reflected cross site scripting vulnerability. A remote user that is able to convince an Operations Manager user to interact with malicious content could execute arbitrary JavaScript in the user's browser.

Affected products

3
  • cpe:2.3:a:pivotal_software:operations_manager:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:pivotal_software:operations_manager:*:*:*:*:*:*:*:*range: >=2.1.0,<2.1.20
    • (no CPE)range: <2.1.20, <2.2.16, <2.3.10, <2.4.3
  • Range: 2.2

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.