A bug exist in the input parameter of Access Manager that allows supply of invalid character to trigger cross-site scripting vulnerability. This affects NetIQ Access Manager 4.5 and 5.0
References
Link | Resource |
---|---|
https://www.microfocus.com/documentation/access-manager/5.0/accessmanager502-release-notes/accessmanager502-release-notes.html | Release Notes Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2022-05-12 12:15
Updated : 2022-05-23 11:31
NVD link : CVE-2021-22531
Mitre link : CVE-2021-22531
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
microfocus
- access_manager