Unrated severityNVD Advisory· Published Feb 6, 2019· Updated Sep 16, 2024
CVE-2019-6504
CVE-2019-6504
Description
Insufficient output sanitization in the Automic Web Interface (AWI), in CA Automic Workload Automation 12.0 to 12.2, allow attackers to potentially conduct persistent cross site scripting (XSS) attacks via a crafted object.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: 12.0 to 12.2
- CA Technologies - A Broadcom Company/CA Automic Workload Automationv5Range: CA Automic Workload Automation 12.0 prior to Automic.Web.Interface 12.0.6 HF2 CA Automic Workload Automation 12.1 prior to Automic.Web.Interface 12.1.3 HF3 CA Automic Workload Automation 12.2 prior to Automic.Web.Interface 12.2.1 HF1
Patches
Vulnerability mechanics
References
7- www.securityfocus.com/bid/106755mitrevdb-entryx_refsource_BID
- communities.ca.com/community/product-vulnerability-response/blog/2019/01/24/ca20190124-01-security-notice-for-ca-automic-workload-automationmitrex_refsource_MISC
- marc.infomitremailing-listx_refsource_BUGTRAQ
- packetstormsecurity.com/files/151325/CA-Automic-Workload-Automation-12.x-Cross-Site-Scripting.htmlmitrex_refsource_MISC
- sec-consult.com/en/blog/advisories/cross-site-scripting-in-ca-automic-workload-automation-web-interface-formerly-automic-automation-engine/mitrex_refsource_MISC
- seclists.org/fulldisclosure/2019/Jan/61mitremailing-listx_refsource_FULLDISC
- support.ca.com/us/product-content/recommended-reading/security-notices/CA20190124-01-security-notice-for-ca-automic-workload-automation.htmlmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.