Vulnerability Description
NetIQ Privileged Account Manager before 3.1 Patch Update 3 allowed cross site scripting attacks via the "type" and "account" parameters of json requests.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Netiq | Privileged Account Manager | <= 3.0 |
Related Weaknesses (CWE)
References
- https://bugzilla.suse.com/show_bug.cgi?id=1001069
- https://www.netiq.com/documentation/privileged-account-manager-3/npam3103-releas
- https://bugzilla.suse.com/show_bug.cgi?id=1001069
- https://www.netiq.com/documentation/privileged-account-manager-3/npam3103-releas
FAQ
What is CVE-2017-7437?
CVE-2017-7437 is a vulnerability with a CVSS score of 4.6 (MEDIUM). NetIQ Privileged Account Manager before 3.1 Patch Update 3 allowed cross site scripting attacks via the "type" and "account" parameters of json requests.
How severe is CVE-2017-7437?
CVE-2017-7437 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-7437?
Check the references section above for vendor advisories and patch information. Affected products include: Netiq Privileged Account Manager.