Han Sahin, November 2014
A Cross-Site Scripting vulnerability was found in EMC M&R (Watch4net)
Alerting Frontend. This issue allows attackers to perform a wide
variety of actions, such as stealing victims' session tokens or login
credentials, performing arbitrary actions on their behalf, logging their
keystrokes, or exploit issues in other areas of Watch4net.
EMC reports that the following products are affected by this
vulnerability:
EMC released the following updated versions that resolve this
vulnerability:
Registered customers can download upgraded software from support.emc.com
at https://support.emc.com/downloads/34247_ViPR-SRM.