First published: Wed May 03 2017(Updated: )
Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have a persistent XSS vulnerability in Framework.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
NetIQ iManager | =2.7 | |
NetIQ iManager | =2.7-sp1 | |
NetIQ iManager | =2.7-sp2 | |
NetIQ iManager | =2.7-sp3 | |
NetIQ iManager | =2.7-sp4 | |
NetIQ iManager | =2.7-sp4_patch1 | |
NetIQ iManager | =2.7-sp4_patch2 | |
NetIQ iManager | =2.7-sp4_patch3 | |
NetIQ iManager | =2.7-sp4_patch4 | |
NetIQ iManager | =2.7-sp5 | |
NetIQ iManager | =2.7-sp6 | |
NetIQ iManager | =2.7-sp7 | |
NetIQ iManager | =2.7-sp7_patch_1 | |
NetIQ iManager | =2.7-sp7_patch_10 | |
NetIQ iManager | =2.7-sp7_patch_2 | |
NetIQ iManager | =2.7-sp7_patch_3 | |
NetIQ iManager | =2.7-sp7_patch_4 | |
NetIQ iManager | =2.7-sp7_patch_5 | |
NetIQ iManager | =2.7-sp7_patch_6 | |
NetIQ iManager | =2.7-sp7_patch_7 | |
NetIQ iManager | =2.7-sp7_patch_8 | |
NetIQ iManager | =2.7-sp7_patch_9 | |
NetIQ iManager | =3.0 | |
NetIQ iManager | =3.0.1 | |
NetIQ iManager | =3.0.2 | |
NetIQ iManager | =3.0.2.1 | |
NetIQ iManager | =3.0.3 | |
NetIQ iManager | =3.0.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7430 is classified as a persistent cross-site scripting (XSS) vulnerability.
To fix CVE-2017-7430, update Novell iManager to version 2.7 SP7 Patch 10 HF1 or later, or update NetIQ iManager to version 3.0.3.1 or later.
CVE-2017-7430 affects Novell iManager versions 2.7.x prior to SP7 Patch 10 HF1 and NetIQ iManager 3.x prior to 3.0.3.1.
While the best solution is to apply the patch, implementing proper input validation can help mitigate the risks associated with CVE-2017-7430.
CVE-2017-7430 can facilitate persistent cross-site scripting attacks which can lead to unauthorized actions on behalf of users.