Cross-site scripting in Fortify Software Security Center - CVE-2019-11649

 

Cross-site scripting in Fortify Software Security Center - CVE-2019-11649

Published: June 19, 2019 / Updated: August 8, 2020


Vulnerability identifier: #VU35819
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear
CVE-ID: CVE-2019-11649
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: OpenText
Affected software:
Fortify Software Security Center

Detailed vulnerability description

The vulnerability allows a remote authenticated user to read and manipulate data.

Cross-Site Scripting vulnerability in Micro Focus Fortify Software Security Center Server, versions 17.2, 18.1, 18.2, has been identified in Micro Focus Software Security Center. The vulnerability could be exploited to execute JavaScript code in user’s browser. The vulnerability could be exploited to execute JavaScript code in user’s browser.


How to mitigate CVE-2019-11649

Install update from vendor's website.

Sources