CVE-2017-14800 Information
Feb 14, 2021
cve
Description
A reflected cross site scripting attack in the NetIQ Access Manager before 4.3.3 using the \typecontainerid\ parameter of the policy editor could allowed code injection into pages of authenticated users.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Reference
https://www.novell.com/support/kb/doc.php?id=7022356
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
CHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
NONE
Base Severity
6.1
Share on: