Palo Alto Networks Security Advisories / CVE-2015-2223

CVE-2015-2223 ESM Console XSS vulnerability

Severity 4.2 · MEDIUM
Attack Vector NETWORK
Attack Complexity HIGH
Privileges Required NONE
User Interaction REQUIRED
Confidentiality Impact LOW
Integrity Impact LOW
Availability Impact NONE


A cross-site scripting vulnerability exists in the web-based console management. This vulnerability has been assigned CVE-2015-2223.

This issue affects the management interface of Traps, where an authenticated administrator may be tricked into injecting malicious JavaScript into the web UI interface.

This issue affects Traps ESM Console version 3.2.1 and earlier

Product Status

Traps ESM Console 3.2<>=
Traps ESM Console 3.1<>=

Severity: MEDIUM

CVSSv3.1 Base Score: 4.2 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N)

Weakness Type

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')


Traps ESM Console and higher; Traps ESM Console and higher

Workarounds and Mitigations


Michael Hendrickx
© 2020 Palo Alto Networks, Inc. All rights reserved.