Platform
other
Component
polarion
Opgelost in
19.2.1
CVE-2019-13935 describes a Cross-Site Scripting (XSS) vulnerability within the webclient component of Siemens AG Polarion. This vulnerability allows an attacker to inject malicious scripts, potentially leading to unauthorized access or data manipulation. The vulnerability affects all versions of Polarion prior to 19.2. A fix is available in version 19.2.
Successful exploitation of CVE-2019-13935 allows an attacker to execute arbitrary JavaScript code within the context of a user's browser session on the Polarion webclient. This could lead to the theft of sensitive information, such as user credentials or project data. An attacker could also leverage this vulnerability to redirect users to malicious websites or deface the Polarion interface. The potential impact is amplified if the Polarion instance is used to manage critical project data or sensitive intellectual property.
CVE-2019-13935 was publicly disclosed on November 27, 2019. No known active exploitation campaigns have been reported. There are no publicly available proof-of-concept exploits. The CVSS score of 3.5 (LOW) indicates a relatively low probability of exploitation under normal circumstances.
Organizations utilizing Siemens Polarion for project management and collaboration are at risk, particularly those running versions prior to 19.2. This includes teams managing sensitive project data, intellectual property, or regulatory compliance documentation. Shared hosting environments where multiple Polarion instances reside on the same infrastructure could also amplify the risk.
disclosure
Exploit Status
EPSS
0.34% (57% percentiel)
CVSS-vector
The primary mitigation for CVE-2019-13935 is to upgrade to Polarion version 19.2 or later, which contains the fix for this vulnerability. If upgrading immediately is not feasible, consider implementing input validation and output encoding measures on the webclient to sanitize user-supplied data. While not a complete solution, these measures can reduce the attack surface. Thoroughly review and update any custom scripts or plugins within the Polarion environment to ensure they do not introduce further XSS vulnerabilities. After upgrading, confirm the fix by attempting to inject a simple XSS payload into a web form and verifying that the script is not executed.
Werk Siemens Polarion bij naar versie 19.2 of hoger. Dit zal de gereflecteerde XSS kwetsbaarheid in de webclient verhelpen.
Kwetsbaarheidsanalyses en kritieke waarschuwingen direct in uw inbox.
CVE-2019-13935 is a reflected XSS vulnerability in the webclient component of Siemens Polarion, allowing attackers to inject malicious scripts. It affects versions prior to 19.2.
Yes, if you are using Siemens Polarion versions earlier than 19.2, you are potentially vulnerable to this XSS attack.
Upgrade to Siemens Polarion version 19.2 or later to resolve the vulnerability. Consider input validation as a temporary mitigation.
Currently, there are no reports of active exploitation campaigns targeting CVE-2019-13935.
Refer to the Siemens Security Notice: https://us-cert.cisa.gov/ics/advisories/icsa-19-313-01
Upload je dependency-bestand en kom direct te weten of deze en andere CVEs jou raken.