CVE-2018-7674: IDM URL Redirection attack
The NetIQ Identity Manager user console, in versions prior to 4.7, is susceptible to URL redirection.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
NetIQ Identity Manager user consoleto a version that resolves this vulnerability.Fixed in 4.7
Event History
Frequently Asked Questions
What is the severity of CVE-2018-7674?
CVE-2018-7674 is rated as medium severity due to its potential impact on user redirection.
How do I fix CVE-2018-7674?
To mitigate CVE-2018-7674, upgrade to NetIQ Identity Manager version 4.7 or later.
What versions of NetIQ Identity Manager are affected by CVE-2018-7674?
NetIQ Identity Manager versions prior to 4.7, specifically up to version 4.6, are affected by CVE-2018-7674.
What type of vulnerability is CVE-2018-7674?
CVE-2018-7674 is a URL redirection vulnerability that can potentially be exploited to redirect users to malicious sites.
Is there a way to prevent exploitation of CVE-2018-7674 without upgrading?
While upgrading is the recommended solution, applying strict input validation on URLs may help mitigate the risk of CVE-2018-7674.