CVE-2016-5755

MEDIUM

NetIQ Access Manager <4.1.2-4.2.2 - CSRF

Title source: llm

Description

NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 was vulnerable to clickjacking attacks due to a missing SAMEORIGIN filter in the "high encryption" setting.

Scores

CVSS v3 6.5
EPSS 0.0013
EPSS Percentile 32.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Classification

CWE
CWE-20
Status published

Affected Products (6)

netiq/access_manager
netiq/access_manager
netiq/access_manager
netiq/access_manager
netiq/access_manager
n/a/NetIQ Access Manager < NetIQ Access Manager

Timeline

Published Mar 23, 2017
Tracked Since Feb 18, 2026