CVE-2016-1598

MEDIUM

NetIQ IDM 4.5 Identity Applications < 4.5.4 - Stored Cross-Site Scripting via Username Field

Title source: llm
STIX 2.1

Description

XSS in NetIQ IDM 4.5 Identity Applications before 4.5.4 allows attackers able to change their username to inject arbitrary HTML code into the Role Assignment administrator HTML pages.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/93833
Various Sources x_refsource_confirm
https://download.novell.com/Download?buildid=xyswDCMsT7I~

Scores

CVSS v3 5.4
EPSS 0.0027
EPSS Percentile 50.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (3)
n/a/NetIQ IDM 4.5 Identity Applications before 4.5.4 NetIQ IDM 4.5 Identity Applications before 4.5.4
novell/identity_manager 4.5
novell/identity_manager_identity_applications < 4.5.3
Published Oct 27, 2016
Tracked Since Feb 18, 2026