CVE-2016-5756: XSS
Multiple components of the web tools in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 were vulnerable to Reflected Cross Site Scripting attacks which could be used to hijack user sessions: nps/servlet/frameservice, nps/servlet/webacc, roma/admin/cntl, roma/jsp/admin/appliance/devicedetailedit.jsp, roma/jsp/admin/managementip/mgmtipdetailsframeset.jsp, roma/jsp/admin/managementip/mgmtipdetailsmiddleframe.jsp, roma/jsp/volsc/monitoring/appliance.jsp, and roma/jsp/volsc/monitoring/graph.jsp.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5756?
CVE-2016-5756 has a medium severity rating due to its potential to hijack user sessions.
How do I fix CVE-2016-5756?
To fix CVE-2016-5756, upgrade to NetIQ Access Manager version 4.1.2 Hot Fix 1 or 4.2.2 or later.
Which versions of NetIQ Access Manager are affected by CVE-2016-5756?
CVE-2016-5756 affects NetIQ Access Manager versions 4.1 prior to Hot Fix 1 and 4.2 prior to version 4.2.2.
What types of attacks can exploit CVE-2016-5756?
CVE-2016-5756 can be exploited through Reflected Cross Site Scripting attacks.
What components of NetIQ Access Manager are vulnerable in CVE-2016-5756?
The vulnerable components include nps/servlet/frameservice, nps/servlet/webacc, and various admin-related paths.