CVE-2017-14799: XSS Vulnerability with ESP URL
Published Mar 1, 2018
·Updated
A cross site scripting attack in handling the ESP login parameter handling in NetIQ Access Manager before 4.3.3 could be used to inject javascript code into the login page.
Affected Software
1 affected component
NetIQ Access Manager<4.3.3
Event History
Mar 1, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-14799?
CVE-2017-14799 is considered a medium severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2017-14799?
To fix CVE-2017-14799, upgrade NetIQ Access Manager to version 4.3.3 or later.
3
What type of attack is possible with CVE-2017-14799?
CVE-2017-14799 allows for cross-site scripting attacks by injecting malicious JavaScript into the login page.
4
What versions of NetIQ Access Manager are affected by CVE-2017-14799?
NetIQ Access Manager versions prior to 4.3.3 are affected by CVE-2017-14799.
5
How can CVE-2017-14799 impact users?
CVE-2017-14799 can compromise user security by allowing attackers to execute arbitrary scripts in the context of the user's session.