CVE-2017-5191: XSS
Published Apr 24, 2017
·Updated
An XSS vulnerability on the /NAGErrors URI in NetIQ Access Manager 4.2 and 4.3 exists because Access Gateway Error pages do not validate the HTTP Referer header.
Affected Software
2 affected components
NetIQ Access Manager=4.2
NetIQ Access Manager=4.3
Event History
Apr 24, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
DescriptionWeakness
Data Sourced
via NVD·06:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-5191?
CVE-2017-5191 is considered a medium severity vulnerability due to its potential for exploitation through XSS attacks.
2
How do I fix CVE-2017-5191?
To mitigate CVE-2017-5191, it is recommended to update to the latest versions of NetIQ Access Manager that address this vulnerability.
3
What impact does CVE-2017-5191 have on my system?
CVE-2017-5191 may allow attackers to execute malicious scripts in the context of the user's session, compromising sensitive data.
4
Is CVE-2017-5191 exploitable remotely?
Yes, CVE-2017-5191 can be exploited remotely if users are tricked into visiting a malicious page that reflects the XSS attack.
5
Which versions of NetIQ Access Manager are affected by CVE-2017-5191?
CVE-2017-5191 affects NetIQ Access Manager versions 4.2 and 4.3.