CVE-2021-38134: Possible Reflected and Stored XSS in OpenText iManager
Published Nov 22, 2024
·Updated
Possible XSS in iManager URL for access Component has been discovered in OpenText™ iManager 3.2.5.0000.
Affected Software
2 affected components
OpenText iManager
MicroFocus Imanager>=3.0<3.2.6
Event History
Nov 22, 2024
CVE Published
via MITRE·03:34 PM
Data Sourced
via MITRE·03:34 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-38134?
CVE-2021-38134 has been classified with a moderate severity due to its potential for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2021-38134?
To fix CVE-2021-38134, update OpenText iManager to version 3.2.5.0001 or later, where the vulnerability has been addressed.
3
What type of vulnerability is CVE-2021-38134?
CVE-2021-38134 is a cross-site scripting (XSS) vulnerability affecting the URL access component of OpenText iManager.
4
Which versions of OpenText iManager are affected by CVE-2021-38134?
CVE-2021-38134 affects OpenText iManager version 3.2.5.0000 and earlier versions.
5
What are the potential impacts of CVE-2021-38134?
The potential impacts of CVE-2021-38134 include the ability for attackers to execute arbitrary scripts in the context of a user's browser.