CVE-2017-7430: XSS
Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have a persistent XSS vulnerability in Framework.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7430?
CVE-2017-7430 is classified as a persistent cross-site scripting (XSS) vulnerability.
How do I fix CVE-2017-7430?
To fix CVE-2017-7430, update Novell iManager to version 2.7 SP7 Patch 10 HF1 or later, or update NetIQ iManager to version 3.0.3.1 or later.
What software versions are affected by CVE-2017-7430?
CVE-2017-7430 affects Novell iManager versions 2.7.x prior to SP7 Patch 10 HF1 and NetIQ iManager 3.x prior to 3.0.3.1.
Is there a workaround for CVE-2017-7430 pending a patch?
While the best solution is to apply the patch, implementing proper input validation can help mitigate the risks associated with CVE-2017-7430.
What type of attack can CVE-2017-7430 facilitate?
CVE-2017-7430 can facilitate persistent cross-site scripting attacks which can lead to unauthorized actions on behalf of users.