First published: Fri Mar 02 2018(Updated: )
A OAuth application in NetIQ Access Manager 4.3 before 4.3.2 and 4.2 before 4.2.4 allowed cross site scripting attacks due to unescaped "description" field that could be specified by the provider.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
NetIQ Access Manager | >=4.2<4.2.4 | |
NetIQ Access Manager | >=4.3<4.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.