CVE-2016-1592: XSS
Published Oct 27, 2016
·Updated
XSS in NetIQ Designer for Identity Manager before 4.5.3 allows remote attackers to inject arbitrary HTML code via the nrfEntitlementReport.do CGI.
Affected Software
1 affected component
NetIQ Identity Manager<=4.5.2
Remediation
Patch Available
Event History
Oct 27, 2016
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2016-1592?
CVE-2016-1592 is classified as a medium severity vulnerability due to its potential for XSS attacks.
2
How do I fix CVE-2016-1592?
To fix CVE-2016-1592, upgrade NetIQ Designer for Identity Manager to version 4.5.3 or later.
3
What types of attacks can CVE-2016-1592 facilitate?
CVE-2016-1592 can facilitate cross-site scripting (XSS) attacks, allowing attackers to inject arbitrary HTML code.
4
Which versions of NetIQ Identity Manager are affected by CVE-2016-1592?
Versions of NetIQ Identity Manager prior to 4.5.3, specifically up to and including 4.5.2, are affected by CVE-2016-1592.
5
Is user interaction required for CVE-2016-1592 to be exploited?
Yes, user interaction may be required for CVE-2016-1592 to facilitate the execution of injected HTML code.