{ "schema_version": "1.4.0", "id": "GHSA-849f-x5xh-fgxg", "modified": "2022-05-14T01:57:33Z", "published": "2022-05-14T01:57:33Z", "aliases": [ "CVE-2015-2420" ], "details": "Cross-site scripting (XSS) vulnerability in Microsoft System Center 2012 Operations Manager Gold before Rollup 8, SP1 before Rollup 10, and R2 before Rollup 7 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka \"System Center Operations Manager Web Console XSS Vulnerability.\"", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2015-2420" }, { "type": "WEB", "url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-086" }, { "type": "WEB", "url": "http://www.securitytracker.com/id/1033245" } ], "database_specific": { "cwe_ids": [ "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2015-08-15T00:59:00Z" } }