First published: Sun Apr 09 2017(Updated: )
OpenIDM through 4.0.0 and 4.5.0 is vulnerable to reflected cross-site scripting (XSS) attacks within the Admin UI, as demonstrated by the _sortKeys parameter to the authzRoles script under managed/user/.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenID | <=4.0.0 | |
OpenID | =4.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7591 has a medium severity rating due to its potential for reflected cross-site scripting attacks.
To fix CVE-2017-7591, update OpenIDM to a version above 4.5.0 or apply relevant patches provided by the vendor.
CVE-2017-7591 affects OpenIDM versions up to and including 4.0.0, as well as version 4.5.0.
CVE-2017-7591 is associated with reflected cross-site scripting (XSS) attacks.
The vulnerability CVE-2017-7591 occurs within the Admin UI, particularly in the authzRoles script under managed/user/.