CVE-2018-1347: NetIQ iManager, versions prior to 3.1, reflected XSS issue
Published Mar 21, 2018
·Updated
The administrative web interface in NetIQ iManager, versions prior to 3.1, are vulnerable to reflected cross site scripting.
Affected Software
1 affected component
NetIQ iManager<3.1
Remediation
Information
Upgrade to iManager 3.1
Event History
Mar 21, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-1347?
CVE-2018-1347 has a medium severity rating due to the reflected cross-site scripting vulnerability it presents.
2
How do I fix CVE-2018-1347?
To fix CVE-2018-1347, upgrade to NetIQ iManager version 3.1 or later.
3
What systems are affected by CVE-2018-1347?
CVE-2018-1347 affects all versions of NetIQ iManager prior to 3.1.
4
What type of vulnerability is CVE-2018-1347?
CVE-2018-1347 is classified as a reflected cross-site scripting (XSS) vulnerability.
5
What can an attacker do with CVE-2018-1347?
An attacker can exploit CVE-2018-1347 to execute arbitrary scripts in the context of a user's session.