CVE-2024-5532
Last modified
CVE-2024-5532 is a medium-severity vulnerability rated 4.8/10 on the CVSS scale. Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ Operations Agent. The XSS vulnerability could allow an attacker with local admin permissions to manipulate the content of the internal status page of the Agent on the local system. This issue affects Operations Agent: 12.20, 12.21, 12.22, 12.23, 12.24, 12.25, 12.26.. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ Operations Agent. The XSS vulnerability could allow an attacker with local admin permissions to manipulate the content of the internal status page of the Agent on the local system. This issue affects Operations Agent: 12.20, 12.21, 12.22, 12.23, 12.24, 12.25, 12.26.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:A/V:C/RE:M/U:Red
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Microfocus | Operations Agent | >= 12.20, <= 12.26 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-5532?
How severe is CVE-2024-5532?
How do I fix CVE-2024-5532?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-55272An issue in Brainasoft Braina v2.8 allows a remote attacker …7.5
- CVE-2024-55279Uguu through 1.8.9 allows Cross Site Scripting (XSS) via Jav…6
- CVE-2024-5528An issue was discovered in GitLab CE/EE affecting all versio…5.4
- CVE-2024-5529The WP QuickLaTeX WordPress plugin before 3.8.8 does not san…4.8
- CVE-2024-5530The ShopLentor – WooCommerce Builder for Elementor & Gutenbe…5.4
- CVE-2024-5531The Ocean Extra plugin for WordPress is vulnerable to Stored…6.4
- CVE-2024-5533The Divi theme for WordPress is vulnerable to Stored Cross-S…5.4
- CVE-2024-55341A stored cross-site scripting (XSS) vulnerability in Piranha…4.7
- CVE-2024-55342A file upload functionality in Piranha CMS 11.1 allows authe…4.7
- CVE-2024-5535Issue summary: Calling the OpenSSL API function SSL_select_n…9.1
- CVE-2024-55354Lucee before 5.4.7.3 LTS and 6 before 6.1.1.118, when an att…8.8
- CVE-2024-55355Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
Are you affected by CVE-2024-5532?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
