CVE-2017-14800

A reflected cross site scripting attack in the NetIQ Access Manager before 4.3.3 using the "typecontainerid" parameter of the policy editor could allowed code injection into pages of authenticated users.
Configurations

Configuration 1 (hide)

cpe:2.3:a:netiq:access_manager:*:*:*:*:*:*:*:*

History

21 Nov 2024, 03:13

Type Values Removed Values Added
CVSS v2 : 4.3
v3 : 6.1
v2 : 4.3
v3 : 5.4
References () https://www.novell.com/support/kb/doc.php?id=7022356 - () https://www.novell.com/support/kb/doc.php?id=7022356 -

07 Nov 2023, 02:39

Type Values Removed Values Added
References (CONFIRM) https://www.novell.com/support/kb/doc.php?id=7022356 - Vendor Advisory () https://www.novell.com/support/kb/doc.php?id=7022356 -

Information

Published : 2018-03-01 20:29

Updated : 2024-11-21 03:13


NVD link : CVE-2017-14800

Mitre link : CVE-2017-14800

CVE.ORG link : CVE-2017-14800


JSON object : View

Products Affected

netiq

  • access_manager
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')