XSS in NetIQ IDM 4.5 Identity Applications before 4.5.4 allows attackers able to change their username to inject arbitrary HTML code into the Role Assignment administrator HTML pages.
References
Link | Resource |
---|---|
https://download.novell.com/Download?buildid=xyswDCMsT7I~ | Patch Vendor Advisory |
http://www.securityfocus.com/bid/93833 |
Configurations
Configuration 1 (hide)
|
Information
Published : 2016-10-27 13:59
Updated : 2016-11-28 12:00
NVD link : CVE-2016-1598
Mitre link : CVE-2016-1598
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
novell
- identity_manager
- identity_manager_identity_applications