First published: Mon Mar 05 2018(Updated: )
NetIQ Privileged Account Manager before 3.1 Patch Update 3 allowed cross site scripting attacks via the "type" and "account" parameters of json requests.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
OpenText NetIQ Privileged Account Manager | <=3.0 | |
OpenText NetIQ Privileged Account Manager | =3.1 | |
OpenText NetIQ Privileged Account Manager | =3.1-hotfix1 | |
OpenText NetIQ Privileged Account Manager | =3.1-hotfix2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7437 has a medium severity rating due to its potential for cross-site scripting (XSS) attacks.
To fix CVE-2017-7437, upgrade to NetIQ Privileged Account Manager version 3.1 Patch Update 3 or later.
CVE-2017-7437 affects NetIQ Privileged Account Manager versions prior to 3.1 Patch Update 3.
The potential impacts of CVE-2017-7437 include unauthorized actions performed by attackers through cross-site scripting.
There are no known effective workarounds for CVE-2017-7437; updating to a patched version is recommended.