← Back

CVE-2019-5314

nvd nist
Published: Sep 13, 2019Modified: Nov 21, 2024

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

Some web components in the ArubaOS software are vulnerable to HTTP Response splitting (CRLF injection) and Reflected XSS. An attacker would be able to accomplish this by sending certain URL parameters that would trigger this vulnerability.

Affected (4)

1 product
Arubaos
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Arubanetworks
Before 6.4.4.20
From 6.5.4.0 to 6.5.4.11
From 6.5.4.12 to 8.2.1.0
From 8.2.1.1 to 8.3.0.0

References (2)

Source: security-alert@hpe.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.