Cross-Site Scripting Vulnerability in Microsoft System Center Operations Manager
CVE-2015-2420

Currently unrated

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
15 August 2015

Summary

This vulnerability in Microsoft System Center 2012 Operations Manager Web Console allows remote attackers to exploit an XSS flaw by injecting arbitrary web scripts or HTML through crafted URLs. Affected versions include those prior to specific rollups, making it critical for users of the software to implement the necessary updates to mitigate potential security risks.

References

EPSS Score

12% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.