CVE-2015-0787: XSS
Published Oct 27, 2016
·Updated
XSS in NetIQ Designer for Identity Manager before 4.5.3 allows remote attackers to inject arbitrary HTML code via the accessMgrDN value of the forgotUser.do CGI.
Affected Software
1 affected component
NetIQ Identity Manager<=4.5.2
Remediation
Patch Available
Event History
Oct 27, 2016
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2015-0787?
CVE-2015-0787 has a medium severity rating due to the potential for XSS attacks.
2
How do I fix CVE-2015-0787?
To fix CVE-2015-0787, upgrade to NetIQ Designer for Identity Manager version 4.5.3 or later.
3
What systems are affected by CVE-2015-0787?
CVE-2015-0787 affects NetIQ Identity Manager versions prior to 4.5.3.
4
Is CVE-2015-0787 a remote exploit?
Yes, CVE-2015-0787 can be exploited remotely by attackers to inject malicious HTML.
5
What is the attack vector for CVE-2015-0787?
The attack vector for CVE-2015-0787 involves manipulating the accessMgrDN value in the forgotUser.do CGI.