CVE-2021-22528: Information leakage vulnerability in NetIQ Access Manager versions prior to version 4.5.4 and 5.0.1
Published Sep 13, 2021
·Updated
Reflected Cross Site Scripting (XSS) vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4
Affected Software
2 affected components
MicroFocus Access Manager>=4.5.0<4.5.4
MicroFocus Access Manager>=5.0<5.0.1
Remediation
Patch Available
Event History
Sep 13, 2021
CVE Published
via MITRE·11:42 AM
Data Sourced
via MITRE·11:42 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-22528?
The severity of CVE-2021-22528 is high with a CVSS score of 5.4.
2
What is the vulnerability description of CVE-2021-22528?
CVE-2021-22528 is a Reflected Cross Site Scripting (XSS) vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4.
3
How does CVE-2021-22528 impact Microfocus Access Manager?
CVE-2021-22528 allows remote attackers to inject malicious scripts into web pages viewed by users of Microfocus Access Manager.
4
How can I fix CVE-2021-22528?
To fix CVE-2021-22528, it is recommended to upgrade to NetIQ Access Manager version 5.0.1 or 4.5.4.
5
Where can I find more information about CVE-2021-22528?
More information about CVE-2021-22528 can be found on the Microfocus support website and the Access Manager documentation.