HomeMicrofocusCVE-2024-5532

CVE-2024-5532

LOW
1.8CVSS
Published: 2024-10-28
Updated: 2025-10-14
AI Analysis

Description

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ Operations Agent.  The XSS vulnerability could allow an attacker with local admin permissions to manipulate the content of the internal status page of the Agent on the local system. This issue affects Operations Agent: 12.20, 12.21, 12.22, 12.23, 12.24, 12.25, 12.26.

CVSS Metrics

Vector
CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:A/V:C/RE:M/U:Red
Attack Vector
local
Complexity
low
Privileges
high
User Action
none
Confidentiality
undefined
Integrity
undefined
Availability
undefined
Weaknesses
CWE-79

Metadata

Primary Vendor
MICROFOCUS
Published
10/28/2024
Last Modified
10/14/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

microfocus : operations_agent

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2024-5532 | LOW Severity | CVEDatabase.com | CVEDatabase.com