CVE-2016-5751
6.1
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD
Description
An unfiltered finalizer target URL in the SAML processing feature in Identity Server in NetIQ Access Manager 4.1 before 4.1.2 HF1 and 4.2 before 4.2.2 could be used to trigger XSS and leak authentication credentials.
Affected (5)
Products: Netiq: Access Manager
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.1 |
References (2)
Source: security@opentext.com
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.