CVE-2020-17465: XSS
Published Aug 31, 2020
·Updated
Dashboards and progressiveProfileForms in ForgeRock Identity Manager before 7.0.0 are vulnerable to stored XSS. The vulnerability affects versions 6.5.0.4, 6.0.0.6.
Affected Software
2 affected components
ForgeRock Identity Manager=6.0.0.6
ForgeRock Identity Manager=6.5.0.4
Event History
Aug 31, 2020
CVE Published
via MITRE·03:27 PM
Data Sourced
via MITRE·03:27 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this security issue?
The vulnerability ID of this security issue is CVE-2020-17465.
2
What is the severity level of CVE-2020-17465?
The severity level of CVE-2020-17465 is medium.
3
Which versions of ForgeRock Identity Manager are affected by CVE-2020-17465?
Versions 6.0.0.6 and 6.5.0.4 of ForgeRock Identity Manager are affected by CVE-2020-17465.
4
What type of vulnerability is CVE-2020-17465?
CVE-2020-17465 is a stored cross-site scripting (XSS) vulnerability.
5
Are there any references related to CVE-2020-17465?
Yes, you can find more information about CVE-2020-17465 in the following references: [Link 1](https://gist.github.com/gajendkmr/261f45e06c41656131a651c920c7f406), [Link 2](https://www.nccgroup.com/us/our-research/?research=Technical+advisories).