Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ Operations Agent. 

The XSS vulnerability could allow an attacker with local admin permissions to manipulate the content of the internal status page of the Agent on the local system.

This issue affects Operations Agent: 12.20, 12.21, 12.22, 12.23, 12.24, 12.25, 12.26.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-46735 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ Operations Agent.  The XSS vulnerability could allow an attacker with local admin permissions to manipulate the content of the internal status page of the Agent on the local system. This issue affects Operations Agent: 12.20, 12.21, 12.22, 12.23, 12.24, 12.25, 12.26.
Fixes

Solution

OpenText™ Operations Agent (OA) Security Bulletin - A low severity stored XSS vulnerability has been discovered. https://portal.microfocus.com/s/article/KM000035731


Workaround

No workaround given by the vendor.

History

Wed, 15 Oct 2025 03:15:00 +0900

Type Values Removed Values Added
First Time appeared Microfocus
Microfocus operations Agent
CPEs cpe:2.3:a:microfocus:operations_agent:*:*:*:*:*:*:*:*
Vendors & Products Microfocus
Microfocus operations Agent
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'}


Mon, 14 Jul 2025 22:45:00 +0900

Type Values Removed Values Added
Metrics epss

{'score': 0.00191}

epss

{'score': 0.00202}


Tue, 29 Oct 2024 23:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 29 Oct 2024 04:00:00 +0900

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ Operations Agent.  The XSS vulnerability could allow an attacker with local admin permissions to manipulate the content of the internal status page of the Agent on the local system. This issue affects Operations Agent: 12.20, 12.21, 12.22, 12.23, 12.24, 12.25, 12.26.
Title A stored XSS vulnerability has been discovered on OpenText™ Operations Agent (OA).
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 1.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/S:N/AU:N/R:A/V:C/RE:M/U:Red'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: OpenText

Published:

Updated: 2024-10-29T13:31:42.019Z

Reserved: 2024-05-30T13:49:13.383Z

Link: CVE-2024-5532

cve-icon Vulnrichment

Updated: 2024-10-29T13:31:37.768Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-28T19:15:15.010

Modified: 2025-10-14T18:07:12.830

Link: CVE-2024-5532

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses