CVE-2024-38493: Broadcom Symantec Privileged Access Management
Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.
A reflected cross-site scripting (XSS) vulnerability exists in the PAM UI web interface. A remote attacker able to convince a PAM user to click on a specially crafted link to the PAM UI web interface could potentially execute arbitrary client-side code in the context of PAM UI.
Affected products
- Broadcom Symantec Privileged Access Management: from 4.1.0, up to and including 4.1.7
Published 2024-07-15. Last modified 2026-06-17.