First published: Thu Mar 23 2017(Updated: )
iManager Admin Console in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 was vulnerable to iFrame manipulation attacks, which could allow remote users to gain access to authentication credentials.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
Micro Focus NetIQ Access Manager | =4.1 | |
Micro Focus NetIQ Access Manager | =4.1-sp1 | |
Micro Focus NetIQ Access Manager | =4.1-sp2 | |
Micro Focus NetIQ Access Manager | =4.2 | |
Micro Focus NetIQ Access Manager | =4.2-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-5757 is considered a high-severity vulnerability due to the potential of iFrame manipulation attacks that compromise user authentication credentials.
To mitigate the risk of CVE-2016-5757, it is essential to upgrade NetIQ Access Manager to version 4.1.2 Hot Fix 1 or 4.2.2.
CVE-2016-5757 affects NetIQ Access Manager versions 4.1 up to 4.1.2 Hot Fix 1 and 4.2 up to 4.2.2.
CVE-2016-5757 is associated with iFrame manipulation attacks that can lead to unauthorized access to authentication credentials.
Any organization using the vulnerable versions of NetIQ Access Manager is at risk from CVE-2016-5757 attacks.