CVE-2016-5755: Input Validation
Published Mar 23, 2017
·Updated
NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 was vulnerable to clickjacking attacks due to a missing SAMEORIGIN filter in the "high encryption" setting.
Affected Software
5 affected components
NetIQ Access Manager=4.1
NetIQ Access Manager=4.1-sp1
NetIQ Access Manager=4.1-sp2
NetIQ Access Manager=4.2
NetIQ Access Manager=4.2-sp1
Event History
Mar 23, 2017
CVE Published
via MITRE·06:36 AM
Data Sourced
via MITRE·06:36 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2016-5755?
CVE-2016-5755 has a medium severity rating due to its vulnerability to clickjacking attacks.
2
How do I fix CVE-2016-5755?
To fix CVE-2016-5755, upgrade to NetIQ Access Manager version 4.1.2 Hot Fix 1, 4.2.2, or later.
3
Which versions of NetIQ Access Manager are affected by CVE-2016-5755?
Versions 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 are affected by CVE-2016-5755.
4
What type of attack is associated with CVE-2016-5755?
CVE-2016-5755 is associated with clickjacking attacks due to a missing SAMEORIGIN filter.
5
Is provided encryption in NetIQ Access Manager sufficient in versions affected by CVE-2016-5755?
No, the security feature related to encryption in affected versions is compromised by the lack of a SAMEORIGIN filter.