CVE Published: 20/04/2017 |
CVE Updated: 05/08/2024 |
CVE Year: 2017 Source: microfocus |
Vendor: n/a |
Product: Identity Server Status : PUBLISHED
CVE-2017-5183 Description
NetIQ Access Manager 4.2.2 and 4.3.x before 4.3.1+, when configured as an Identity Server, has XSS in the AssertionConsumerServiceURL field of a signed AuthnRequest in a samlp:AuthnRequest document.