Executive brief
Veritas InfoScale Operations Manager (VIOM), a tool used for managing complex data center storage and server environments, is vulnerable to a cross-site scripting (XSS) flaw. This issue could allow an attacker to execute malicious scripts in the browser of a legitimate user who is logged into the management console. If exploited, this could lead to the theft of session cookies, unauthorized actions performed on behalf of the user, or the defacement of the management interface.
Technical details
Veritas InfoScale Operations Manager (VIOM) 9.1.3 contains a cross-site scripting (XSS) vulnerability. While the specific vulnerable parameter or component within the web application is not detailed in the advisory, XSS typically occurs when the application fails to properly sanitize user-supplied input before including it in a web page. An attacker could exploit this by tricking a user into clicking a malicious link or visiting a compromised page, leading to the execution of arbitrary JavaScript in the context of the victim's session. This can be used to hijack sessions or perform unauthorized administrative actions. Users are advised to check for security bulletins from Veritas for patching information.
Affected products
- Veritas InfoScale Operations Manager (VIOM) 9.1.3
Timeline
- 2026-05-20: disclosed
- 2026-05-20: advisory
References
- https://supportinfoscale.cloud.com/support-home/kbsearch/article?articleNumber=1000766080&articleTitle=InfoScale_Operations_Manager_IOM_web_application_Security_Bulletin_for_CVE_2026_44923_CVE_2026_44924_and_CVE_2026_44925
- https://www.veritas.com/support/en_US/doc/120571566-166757640-0/viom_tot_v118836641-166757640