DNA View

CVE-2017-7427

Low
Low Medium High Critical
CVSS Score
Published: Mar 05, 2018
Last Modified: Nov 21, 2024

Vulnerability Description

Multiple cross site scripting attacks were found in the Identity Manager Plug-in, hosted on iManager 2.7.7.7, before Identity Manager 4.6.1. In certain scenarios it was possible to execute arbitrary JavaScript code in the context of vulnerable application, via user.Context in the Object Selector, via vdtData in the Version discovery and via nextFrame in the Object Inspector and via Host GUID in the System details plugins.

Known Affected Software

3 configuration(s) from 1 vendor(s)

identity_manager
Version:
4.0.2
CPE:
cpe:2.3:a:netiq:identity_manager:4.0.2:*:*:*:*:*:*:*
identity_manager
Version:
4.5
CPE:
cpe:2.3:a:netiq:identity_manager:4.5:*:*:*:*:*:*:*
identity_manager
Version:
4.6
CPE:
cpe:2.3:a:netiq:identity_manager:4.6:*:*:*:*:*:*:*
This vulnerability affects 3 software configuration(s). Ensure you patch all affected systems.

Severity Details

out of 10.0
Low

Weakness Type (CWE)

CWE-79 Top 25 #1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Exploit Likelihood
High
Typical Severity
Medium
OWASP Top 10
A03:2021-Injection
Abstraction Level
Base

Key Information

Published Date
March 05, 2018