Database/Control plane, storage & DevOps

Vertiv Avocent UMG-4000 universal management gateway: An authenticated admin can plant a maliciously named file
Impact
An authenticated admin can plant a maliciously named file in the web application that executes JavaScript every time any user (including a higher-privileged one) browses to the page listing it — a stepping stone to hijacking another operator's session on the KVM gateway.
Who can reach it
Requires an authenticated administrator account to upload/name the malicious file; the payload then fires against any user who later views that page.
What to do
Same fixed firmware/software build as the UMG-4000 command-injection issue (CVE-2019-9507) — apply both in the same maintenance window since they land in the same release. One flash per gateway.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.