CVE-2021-22531

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
12/05/2022
Last modified:
07/11/2023

Description

A bug exist in the input parameter of Access Manager that allows supply of invalid character to trigger cross-site scripting vulnerability. This affects NetIQ Access Manager 4.5 and 5.0

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:microfocus:access_manager:4.5:-:*:*:*:*:*:*
cpe:2.3:a:microfocus:access_manager:4.5:hotfix1:*:*:*:*:*:*
cpe:2.3:a:microfocus:access_manager:4.5:sp1:*:*:*:*:*:*
cpe:2.3:a:microfocus:access_manager:4.5:sp1_hotfix1:*:*:*:*:*:*
cpe:2.3:a:microfocus:access_manager:4.5:sp1_hotfix2:*:*:*:*:*:*
cpe:2.3:a:microfocus:access_manager:4.5:sp2:*:*:*:*:*:*
cpe:2.3:a:microfocus:access_manager:4.5:sp2_hotfix1:*:*:*:*:*:*
cpe:2.3:a:microfocus:access_manager:4.5:sp2_hotfix2:*:*:*:*:*:*
cpe:2.3:a:microfocus:access_manager:4.5:sp3:*:*:*:*:*:*
cpe:2.3:a:microfocus:access_manager:4.5:sp3_hotfix1:*:*:*:*:*:*
cpe:2.3:a:microfocus:access_manager:4.5:sp3_patch3:*:*:*:*:*:*
cpe:2.3:a:microfocus:access_manager:4.5:sp4:*:*:*:*:*:*
cpe:2.3:a:microfocus:access_manager:4.5:sp5:*:*:*:*:*:*
cpe:2.3:a:microfocus:access_manager:5.0:-:*:*:*:*:*:*
cpe:2.3:a:microfocus:access_manager:5.0:sp1:*:*:*:*:*:*