PT-2022-9251 · Netiq · Netiq Access Manager

Stefan Stojanovski

·

Published

2022-05-12

·

Updated

2022-05-23

·

CVE-2021-22531

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions NetIQ Access Manager versions 4.5 through 5.0
Description A bug exists in the input parameter of Access Manager that allows the supply of invalid characters to trigger a cross-site scripting issue.
Recommendations For versions 4.5 and 5.0, consider restricting input to prevent the supply of invalid characters until a fix is available. As a temporary workaround, restrict access to the vulnerable input parameter to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-22531

Affected Products

Netiq Access Manager