First published: Tue Jul 13 2004(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in the primary and management web interfaces in Netegrity IdentityMinder Web Edition 5.6 allows remote attackers to execute script as other users via (1) script that starts with %00 in the numOfExpressions parameter or (2) the mobjtype parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Broadcom CA IdentityMinder | =web_5.6 | |
Broadcom CA IdentityMinder | =web_5.6_sp1 | |
Netegrity Policy Server | =5.5 | |
Broadcom CA IdentityMinder | =web_5.6_sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0672 is classified as a medium severity vulnerability due to its potential for exploitation via cross-site scripting.
To mitigate CVE-2004-0672, it is recommended to update Netegrity IdentityMinder Web Edition to the latest patched version.
CVE-2004-0672 can be exploited via crafted input parameters, specifically 'numOfExpressions' and 'mobjtype', allowing execution of malicious scripts.
CVE-2004-0672 affects users of Netegrity IdentityMinder versions 5.6, 5.6 SP1, and 5.6 SP2.
CVE-2004-0672 facilitates cross-site scripting attacks, which can lead to unauthorized script execution in the context of other users.