CVE-2017-5191
MEDIUMNetIQ Access Manager 4.2-4.3 - XSS
Title source: llmDescription
An XSS vulnerability on the /NAGErrors URI in NetIQ Access Manager 4.2 and 4.3 exists because Access Gateway Error pages do not validate the HTTP Referer header.
Scores
CVSS v3
6.1
EPSS
0.0024
EPSS Percentile
47.0%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Classification
CWE
CWE-79
Status
published
Affected Products (3)
netiq/access_manager
netiq/access_manager
n/a/NetIQ Access Manager 4.2 and NetIQ Access Manager 4.3
< NetIQ Access Manager 4.2 and NetIQ Access Manager 4.3
Timeline
Published
Apr 24, 2017
Tracked Since
Feb 18, 2026