Reflected XSS in Pivotal Operations Manager
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.2epss 0.8%
exploitation probability
0.8%top 43% of all CVEs
observed exploitation
nono source reports it
Pivotal Operations Manager, 2.1.x versions prior to 2.1.20, 2.2.x versions prior to 2.2.16, 2.3.x versions prior to 2.3.10, 2.4.x versions prior to 2.4.3, contains a reflected cross site scripting vulnerability. A remote user that is able to convince an Operations Manager user to interact with malicious content could execute arbitrary JavaScript in the user's browser.
CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:H/A:L
Affected products
Pivotal · Pivotal Ops Manager