Lucene search

K
cveMicrofocusCVE-2021-22531
HistoryMay 12, 2022 - 7:15 p.m.

CVE-2021-22531

2022-05-1219:15:48
CWE-79
microfocus
web.nvd.nist.gov
48
security
bug
input parameter
access manager
xss
netiq access manager

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

31.3%

A bug exist in the input parameter of Access Manager that allows supply of invalid character to trigger cross-site scripting vulnerability. This affects NetIQ Access Manager 4.5 and 5.0

Affected configurations

Nvd
Node
microfocusaccess_managerMatch4.5-
OR
microfocusaccess_managerMatch4.5hotfix1
OR
microfocusaccess_managerMatch4.5sp1
OR
microfocusaccess_managerMatch4.5sp1_hotfix1
OR
microfocusaccess_managerMatch4.5sp1_hotfix2
OR
microfocusaccess_managerMatch4.5sp2
OR
microfocusaccess_managerMatch4.5sp2_hotfix1
OR
microfocusaccess_managerMatch4.5sp2_hotfix2
OR
microfocusaccess_managerMatch4.5sp3
OR
microfocusaccess_managerMatch4.5sp3_hotfix1
OR
microfocusaccess_managerMatch4.5sp3_patch3
OR
microfocusaccess_managerMatch4.5sp4
OR
microfocusaccess_managerMatch4.5sp5
OR
microfocusaccess_managerMatch5.0-
OR
microfocusaccess_managerMatch5.0sp1
VendorProductVersionCPE
microfocusaccess_manager4.5cpe:2.3:a:microfocus:access_manager:4.5:-:*:*:*:*:*:*
microfocusaccess_manager4.5cpe:2.3:a:microfocus:access_manager:4.5:hotfix1:*:*:*:*:*:*
microfocusaccess_manager4.5cpe:2.3:a:microfocus:access_manager:4.5:sp1:*:*:*:*:*:*
microfocusaccess_manager4.5cpe:2.3:a:microfocus:access_manager:4.5:sp1_hotfix1:*:*:*:*:*:*
microfocusaccess_manager4.5cpe:2.3:a:microfocus:access_manager:4.5:sp1_hotfix2:*:*:*:*:*:*
microfocusaccess_manager4.5cpe:2.3:a:microfocus:access_manager:4.5:sp2:*:*:*:*:*:*
microfocusaccess_manager4.5cpe:2.3:a:microfocus:access_manager:4.5:sp2_hotfix1:*:*:*:*:*:*
microfocusaccess_manager4.5cpe:2.3:a:microfocus:access_manager:4.5:sp2_hotfix2:*:*:*:*:*:*
microfocusaccess_manager4.5cpe:2.3:a:microfocus:access_manager:4.5:sp3:*:*:*:*:*:*
microfocusaccess_manager4.5cpe:2.3:a:microfocus:access_manager:4.5:sp3_hotfix1:*:*:*:*:*:*
Rows per page:
1-10 of 151

CNA Affected

[
  {
    "product": "NetIQ Access Manager",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "4.5, 5.0"
      }
    ]
  }
]

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

31.3%

Related for CVE-2021-22531