Vulnerability Details CVE-2019-3776
Pivotal Operations Manager, 2.1.x versions prior to 2.1.20, 2.2.x versions prior to 2.2.16, 2.3.x versions prior to 2.3.10, 2.4.x versions prior to 2.4.3, contains a reflected cross site scripting vulnerability. A remote user that is able to convince an Operations Manager user to interact with malicious content could execute arbitrary JavaScript in the user's browser.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 41.7%
CVSS Severity
CVSS v3 Score 7.2
CVSS v2 Score 3.5
Products affected by CVE-2019-3776
-
cpe:2.3:a:pivotal_software:operations_manager:2.1.0
-
cpe:2.3:a:pivotal_software:operations_manager:2.1.1
-
cpe:2.3:a:pivotal_software:operations_manager:2.1.10
-
cpe:2.3:a:pivotal_software:operations_manager:2.1.11
-
cpe:2.3:a:pivotal_software:operations_manager:2.1.12
-
cpe:2.3:a:pivotal_software:operations_manager:2.1.13
-
cpe:2.3:a:pivotal_software:operations_manager:2.1.14
-
cpe:2.3:a:pivotal_software:operations_manager:2.1.15
-
cpe:2.3:a:pivotal_software:operations_manager:2.1.16
-
cpe:2.3:a:pivotal_software:operations_manager:2.1.17
-
cpe:2.3:a:pivotal_software:operations_manager:2.1.18
-
cpe:2.3:a:pivotal_software:operations_manager:2.1.19
-
cpe:2.3:a:pivotal_software:operations_manager:2.1.2
-
cpe:2.3:a:pivotal_software:operations_manager:2.1.3
-
cpe:2.3:a:pivotal_software:operations_manager:2.1.4
-
cpe:2.3:a:pivotal_software:operations_manager:2.1.5
-
cpe:2.3:a:pivotal_software:operations_manager:2.1.6
-
cpe:2.3:a:pivotal_software:operations_manager:2.1.7
-
cpe:2.3:a:pivotal_software:operations_manager:2.1.8
-
cpe:2.3:a:pivotal_software:operations_manager:2.1.9
-
cpe:2.3:a:pivotal_software:operations_manager:2.2.0
-
cpe:2.3:a:pivotal_software:operations_manager:2.2.1
-
cpe:2.3:a:pivotal_software:operations_manager:2.2.10
-
cpe:2.3:a:pivotal_software:operations_manager:2.2.11
-
cpe:2.3:a:pivotal_software:operations_manager:2.2.12
-
cpe:2.3:a:pivotal_software:operations_manager:2.2.13
-
cpe:2.3:a:pivotal_software:operations_manager:2.2.14
-
cpe:2.3:a:pivotal_software:operations_manager:2.2.15
-
cpe:2.3:a:pivotal_software:operations_manager:2.2.2
-
cpe:2.3:a:pivotal_software:operations_manager:2.2.3
-
cpe:2.3:a:pivotal_software:operations_manager:2.2.4
-
cpe:2.3:a:pivotal_software:operations_manager:2.2.5
-
cpe:2.3:a:pivotal_software:operations_manager:2.2.6
-
cpe:2.3:a:pivotal_software:operations_manager:2.2.7
-
cpe:2.3:a:pivotal_software:operations_manager:2.2.8
-
cpe:2.3:a:pivotal_software:operations_manager:2.2.9
-
cpe:2.3:a:pivotal_software:operations_manager:2.3.0
-
cpe:2.3:a:pivotal_software:operations_manager:2.3.1
-
cpe:2.3:a:pivotal_software:operations_manager:2.3.2
-
cpe:2.3:a:pivotal_software:operations_manager:2.3.3
-
cpe:2.3:a:pivotal_software:operations_manager:2.3.4
-
cpe:2.3:a:pivotal_software:operations_manager:2.3.5
-
cpe:2.3:a:pivotal_software:operations_manager:2.3.6
-
cpe:2.3:a:pivotal_software:operations_manager:2.3.7
-
cpe:2.3:a:pivotal_software:operations_manager:2.3.8
-
cpe:2.3:a:pivotal_software:operations_manager:2.3.9
-
cpe:2.3:a:pivotal_software:operations_manager:2.4.0
-
cpe:2.3:a:pivotal_software:operations_manager:2.4.1
-
cpe:2.3:a:pivotal_software:operations_manager:2.4.2