An XSS vulnerability on the /NAGErrors URI in NetIQ Access Manager 4.2 and 4.3 exists because Access Gateway Error pages do not validate the HTTP Referer header.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: microfocus

Published: 2017-04-24T18:00:00

Updated: 2024-08-05T14:55:35.459Z

Reserved: 2017-01-06T00:00:00

Link: CVE-2017-5191

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2017-04-24T18:59:00.600

Modified: 2023-11-07T02:49:22.417

Link: CVE-2017-5191

cve-icon Redhat

No data.