First published: Wed Mar 28 2018(Updated: )
The NetIQ Identity Manager user console, in versions prior to 4.7, is susceptible to URL redirection.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
Micro Focus Identity Manager | <=4.6 |
Upgrade to NetIQ Identity Manager 4.7.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-7674 is rated as medium severity due to its potential impact on user redirection.
To mitigate CVE-2018-7674, upgrade to NetIQ Identity Manager version 4.7 or later.
NetIQ Identity Manager versions prior to 4.7, specifically up to version 4.6, are affected by CVE-2018-7674.
CVE-2018-7674 is a URL redirection vulnerability that can potentially be exploited to redirect users to malicious sites.
While upgrading is the recommended solution, applying strict input validation on URLs may help mitigate the risk of CVE-2018-7674.