CVE-2016-5751: XSS
Published Mar 23, 2017
·Updated
An unfiltered finalizer target URL in the SAML processing feature in Identity Server in NetIQ Access Manager 4.1 before 4.1.2 HF1 and 4.2 before 4.2.2 could be used to trigger XSS and leak authentication credentials.
Affected Software
5 affected components
NetIQ Access Manager=4.1
NetIQ Access Manager=4.1-sp1
NetIQ Access Manager=4.1-sp2
NetIQ Access Manager=4.2
NetIQ Access Manager=4.2-sp1
Event History
Mar 23, 2017
CVE Published
via MITRE·06:36 AM
Data Sourced
via MITRE·06:36 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2016-5751?
CVE-2016-5751 is rated as a medium severity vulnerability due to its potential for XSS attacks and credential leakage.
2
What versions of NetIQ Access Manager are affected by CVE-2016-5751?
CVE-2016-5751 affects NetIQ Access Manager versions 4.1 before 4.1.2 HF1 and 4.2 before 4.2.2.
3
How do I fix CVE-2016-5751?
To fix CVE-2016-5751, update your NetIQ Access Manager to version 4.1.2 HF1 or 4.2.2 or later.
4
What type of vulnerability is CVE-2016-5751?
CVE-2016-5751 is a security vulnerability that allows for cross-site scripting (XSS) exploitation.
5
What impact does CVE-2016-5751 have on security?
CVE-2016-5751 can lead to unauthorized access and potential theft of authentication credentials through unfiltered URLs.