CVE-2017-7419: NetIQ Access Manager OAuth Consent screen XSS attack
Published Mar 2, 2018
·Updated
A OAuth application in NetIQ Access Manager 4.3 before 4.3.2 and 4.2 before 4.2.4 allowed cross site scripting attacks due to unescaped "description" field that could be specified by the provider.
Affected Software
2 affected components
NetIQ Access Manager>=4.2<4.2.4
NetIQ Access Manager>=4.3<4.3.2
Event History
Mar 2, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-7419?
CVE-2017-7419 is considered a medium severity vulnerability due to its potential for cross site scripting attacks.
2
How do I fix CVE-2017-7419?
To fix CVE-2017-7419, upgrade NetIQ Access Manager to version 4.2.4 or 4.3.2 or later.
3
What software versions are affected by CVE-2017-7419?
NetIQ Access Manager versions prior to 4.2.4 and 4.3.2 are affected by CVE-2017-7419.
4
What type of attack is enabled by CVE-2017-7419?
CVE-2017-7419 allows attackers to conduct cross site scripting attacks due to an unescaped description field.
5
Who is impacted by CVE-2017-7419?
Organizations using vulnerable versions of NetIQ Access Manager are at risk of attack due to CVE-2017-7419.