CVE Database
/

CVE-2024-38493

Back to search

CVE-2024-38493

Published: Jul 15, 2024

Modified: Oct 27, 2024

PUBLISHED

Description

A reflected cross-site scripting (XSS) vulnerability exists in the PAM UI web interface. A remote attacker able to convince a PAM user to click on a specially crafted link to the PAM UI web interface could potentially execute arbitrary client-side code in the context of PAM UI.

VendorProductVersions

Broadcom

Symantec Privileged Access Management

affected
4.1.0 - 4.1.7
affected
3.4.6

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now