Vulnerability Description
Multiple components of the web tools in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 were vulnerable to Reflected Cross Site Scripting attacks which could be used to hijack user sessions: nps/servlet/frameservice, nps/servlet/webacc, roma/admin/cntl, roma/jsp/admin/appliance/devicedetail_edit.jsp, roma/jsp/admin/managementip/mgmt_ip_details_frameset.jsp, roma/jsp/admin/managementip/mgmt_ip_details_middleframe.jsp, roma/jsp/volsc/monitoring/appliance.jsp, and roma/jsp/volsc/monitoring/graph.jsp.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Netiq | Access Manager | 4.1 |
Related Weaknesses (CWE)
References
- https://www.novell.com/support/kb/doc.php?id=7017813
- https://www.novell.com/support/kb/doc.php?id=7017813
FAQ
What is CVE-2016-5756?
CVE-2016-5756 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Multiple components of the web tools in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 were vulnerable to Reflected Cross Site Scripting attacks which could be used to hijack use...
How severe is CVE-2016-5756?
CVE-2016-5756 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-5756?
Check the references section above for vendor advisories and patch information. Affected products include: Netiq Access Manager.