First published: Fri Mar 02 2018(Updated: )
Reflected XSS in the NetIQ Access Manager before 4.3.3 allowed attackers to reflect back xss into the called page using the url parameter.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
NetIQ Access Manager | <4.3.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-14801 is considered a medium severity vulnerability due to its reflected XSS impact.
To fix CVE-2017-14801, upgrade your NetIQ Access Manager to version 4.3.3 or later.
CVE-2017-14801 is a reflected cross-site scripting (XSS) vulnerability.
The vulnerability affects NetIQ Access Manager versions prior to 4.3.3.
Attackers can exploit CVE-2017-14801 to inject and execute malicious scripts in the context of the user's browser.