CVE-2016-5751

An unfiltered finalizer target URL in the SAML processing feature in Identity Server in NetIQ Access Manager 4.1 before 4.1.2 HF1 and 4.2 before 4.2.2 could be used to trigger XSS and leak authentication credentials.
References
Link Resource
https://www.novell.com/support/kb/doc.php?id=7017808 Exploit Third Party Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:netiq:access_manager:4.2:sp1:*:*:*:*:*:*
cpe:2.3:a:netiq:access_manager:4.1:sp2:*:*:*:*:*:*
cpe:2.3:a:netiq:access_manager:4.1:*:*:*:*:*:*:*
cpe:2.3:a:netiq:access_manager:4.2:*:*:*:*:*:*:*
cpe:2.3:a:netiq:access_manager:4.1:sp1:*:*:*:*:*:*

Information

Published : 2017-03-22 23:59

Updated : 2017-03-24 07:51


NVD link : CVE-2016-5751

Mitre link : CVE-2016-5751


JSON object : View

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Advertisement

dedicated server usa

Products Affected

netiq

  • access_manager