Medium severity6.1NVD Advisory· Published Sep 13, 2019· Updated Jun 17, 2026
CVE-2019-5314
CVE-2019-5314
Description
Some web components in the ArubaOS software are vulnerable to HTTP Response splitting (CRLF injection) and Reflected XSS. An attacker would be able to accomplish this by sending certain URL parameters that would trigger this vulnerability.
Affected products
3cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*range: <6.4.4.20
- (no CPE)
- Aruba/ArubaOSdescription
Patches
Vulnerability mechanics
References
1- www.arubanetworks.com/assets/alert/ARUBA-PSA-2019-004.txtnvdVendor Advisory
News mentions
0No linked articles in our index yet.