CVE-2017-7419
02.03.2018, 20:29
A OAuth application in NetIQ Access Manager 4.3 before 4.3.2 and 4.2 before 4.2.4 allowed cross site scripting attacks due to unescaped "description" field that could be specified by the provider.
| Vendor | Product | Version |
|---|---|---|
| netiq | access_manager | 4.2 ≤ 𝑥 < 4.2.4 |
| netiq | access_manager | 4.3 ≤ 𝑥 < 4.3.2 |
𝑥
= Vulnerable software versions