Vulnerability Note VU#567774
Imperva SecureSphere management GUI contains an XSS vulnerability
An XSS vulnerability exists in the Imperva SecureSphere management GUI.
Dell SecureWorks' SWRX-2011-001 advisory states:
"A vulnerability exists in Imperva SecureSphere due to improper validation of user-controlled input. User-controllable input is not properly sanitized for illegal or malicious content prior to being stored and later returned to an administrator in dynamically generated web content. Remote attackers could leverage this issue to conduct persistent cross-site scripting attacks. When the malicious content is viewed, arbitrary script or HTML code injected into the affected database field will be executed in the SecureSphere administrative user’s browser session in the security context of the SecureSphere administrative GUI. Successful exploitation may aid an attacker in retrieving session cookies, stealing recently submitted data, or launching further attacks."
An attacker may be able to execute arbitrary script in the security context of the user's browser session accessing the management GUI.
Apply an Update
These patches can be downloaded from Imperva's FTP site. Imperva credentials are required to access the FTP site.
Vendor Information (Learn More)
|Vendor||Status||Date Notified||Date Updated|
|Imperva, Inc.||Affected||-||31 May 2011|
CVSS Metrics (Learn More)
Thanks to Sean Talbot of Dell SecureWorks for reporting this vulnerability.
This document was written by Jared Allar.
- CVE IDs: CVE-2011-0767
- Date Public: 23 May 2011
- Date First Published: 31 May 2011
- Date Last Updated: 31 May 2011
- Severity Metric: 1.61
- Document Revision: 13
If you have feedback, comments, or additional information about this vulnerability, please send us email.