Tenable SecurityCenter < 5.19.0 Multiple XSS Vulnerabilities (TNS-2021-14)

medium Nessus Plugin ID 152985

Synopsis

An application installed on the remote host is affected by multiple vulnerabilities.

Description

According to its self-reported version, the Tenable SecurityCenter application installed on the remote host is less than 5.19.0 and is therefore affected by multiple vulnerabilities in the following components:
- Bootstrap
- SimpleSAML

Note that successful exploitation of the most serious issues can result in the execution of untrusted code.

Solution

Upgrade to 5.19.0 or later.

See Also

https://www.tenable.com/security/tns-2021-14

Plugin Details

Severity: Medium

ID: 152985

File Name: securitycenter_5_19_0_tns_2021_08_XSS.nasl

Version: 1.5

Type: local

Agent: unix

Family: Misc.

Published: 9/3/2021

Updated: 12/1/2023

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.7

CVSS v2

Risk Factor: Medium

Base Score: 4.3

Temporal Score: 3.6

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS Score Source: CVE-2020-11022

CVSS v3

Risk Factor: Medium

Base Score: 6.1

Temporal Score: 5.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Temporal Vector: CVSS:3.0/E:F/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:tenable:securitycenter

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 9/1/2021

Vulnerability Publication Date: 7/22/2021

Reference Information

CVE: CVE-2016-10735, CVE-2018-14040, CVE-2018-14042, CVE-2018-20676, CVE-2018-20677, CVE-2019-8331, CVE-2020-11022