NetIQ Access Manager CVE-2018-7678 Cross Site Scripting Vulnerability
BID:103421
CVE-2018-7678 |Info
NetIQ Access Manager CVE-2018-7678 Cross Site Scripting Vulnerability
| Bugtraq ID: | 103421 |
| Class: | Input Validation Error |
| CVE: |
CVE-2018-7678 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 13 2018 12:00AM |
| Updated: | Mar 13 2018 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
NetIQ Access Manager 4.4 NetIQ Access Manager 4.3 |
| Not Vulnerable: |
NetIQ Access Manager 4.4 SP1 |
Discussion
NetIQ Access Manager CVE-2018-7678 Cross Site Scripting Vulnerability
NetIQ Access Manager is prone to a cross-site scripting vulnerability because it fails to sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
NetIQ Access Manager 4.3 and 4.4 are vulnerable.
NetIQ Access Manager is prone to a cross-site scripting vulnerability because it fails to sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
NetIQ Access Manager 4.3 and 4.4 are vulnerable.
Exploit / POC
NetIQ Access Manager CVE-2018-7678 Cross Site Scripting Vulnerability
An attacker can exploit the issue by enticing an unsuspecting user to visit a specially crafted URL.
An attacker can exploit the issue by enticing an unsuspecting user to visit a specially crafted URL.
Solution / Fix
NetIQ Access Manager CVE-2018-7678 Cross Site Scripting Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
NetIQ Access Manager CVE-2018-7678 Cross Site Scripting Vulnerability
References:
References: