First published: Thu Oct 27 2016(Updated: )
XSS in NetIQ IDM 4.5 Identity Applications before 4.5.4 allows attackers able to change their username to inject arbitrary HTML code into the Role Assignment administrator HTML pages.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
Micro Focus Identity Manager | =4.5 | |
Novell Identity Manager | <=4.5.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1598 is rated as a medium severity vulnerability due to its potential for cross-site scripting (XSS) exploitation.
To fix CVE-2016-1598, update to Novell Identity Manager version 4.5.4 or later.
Attackers can exploit CVE-2016-1598 to inject arbitrary HTML and JavaScript into the Role Assignment administrator pages.
CVE-2016-1598 affects Novell Identity Manager 4.5 and Novell Identity Manager Identity Applications versions up to 4.5.3.
CVE-2016-1598 requires the attacker to have the ability to change their username, which typically means authentication is necessary for exploitation.