CVE-2016-1598: XSS
XSS in NetIQ IDM 4.5 Identity Applications before 4.5.4 allows attackers able to change their username to inject arbitrary HTML code into the Role Assignment administrator HTML pages.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1598?
CVE-2016-1598 is rated as a medium severity vulnerability due to its potential for cross-site scripting (XSS) exploitation.
How do I fix CVE-2016-1598?
To fix CVE-2016-1598, update to Novell Identity Manager version 4.5.4 or later.
What types of attacks can be performed using CVE-2016-1598?
Attackers can exploit CVE-2016-1598 to inject arbitrary HTML and JavaScript into the Role Assignment administrator pages.
What software is affected by CVE-2016-1598?
CVE-2016-1598 affects Novell Identity Manager 4.5 and Novell Identity Manager Identity Applications versions up to 4.5.3.
Can CVE-2016-1598 be exploited without authentication?
CVE-2016-1598 requires the attacker to have the ability to change their username, which typically means authentication is necessary for exploitation.