CVE-2017-7437: Cross site scripting attacks against NetIQ Privileged Account Manager
Published Mar 5, 2018
·Updated
NetIQ Privileged Account Manager before 3.1 Patch Update 3 allowed cross site scripting attacks via the "type" and "account" parameters of json requests.
Affected Software
4 affected components
NetIQ Privileged Account Manager<=3.0
NetIQ Privileged Account Manager=3.1
NetIQ Privileged Account Manager=3.1-hotfix1
NetIQ Privileged Account Manager=3.1-hotfix2
Event History
Mar 5, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-7437?
CVE-2017-7437 has a medium severity rating due to its potential for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2017-7437?
To fix CVE-2017-7437, upgrade to NetIQ Privileged Account Manager version 3.1 Patch Update 3 or later.
3
What software is affected by CVE-2017-7437?
CVE-2017-7437 affects NetIQ Privileged Account Manager versions prior to 3.1 Patch Update 3.
4
What are the potential impacts of CVE-2017-7437?
The potential impacts of CVE-2017-7437 include unauthorized actions performed by attackers through cross-site scripting.
5
Are there any workarounds for CVE-2017-7437?
There are no known effective workarounds for CVE-2017-7437; updating to a patched version is recommended.