Medium severity6.1NVD Advisory· Published Apr 24, 2017· Updated May 13, 2026
CVE-2017-5191
CVE-2017-5191
Description
An XSS vulnerability on the /NAGErrors URI in NetIQ Access Manager 4.2 and 4.3 exists because Access Gateway Error pages do not validate the HTTP Referer header.
Affected products
3cpe:2.3:a:netiq:access_manager:4.2:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:netiq:access_manager:4.2:*:*:*:*:*:*:*
- cpe:2.3:a:netiq:access_manager:4.3:*:*:*:*:*:*:*
- Range: NetIQ Access Manager 4.2 and NetIQ Access Manager 4.3
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.