DOM cross site scripting attack against NetIQ Privileged Account Manager
Description
NetIQ Privileged Account Manager before 3.1 Patch Update 3 allowed cross site scripting attacks via javascript DOM modification using the supplied cookie parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
NetIQ Privileged Account Manager before 3.1 Patch Update 3 is vulnerable to DOM-based XSS via a crafted cookie parameter.
Vulnerability
NetIQ Privileged Account Manager (NPAM) versions prior to 3.1 Patch Update 3 (3.1.0.3) are vulnerable to a cross-site scripting (XSS) attack. The vulnerability allows JavaScript DOM modification through a supplied cookie parameter, meaning the application does not properly sanitize or validate cookie values before using them in the DOM. [1]
Exploitation
An attacker can craft a malicious cookie value containing JavaScript code. When a victim's browser loads a page in NPAM that reads and uses this cookie parameter without sanitization, the injected script executes in the context of the victim's session. The attacker may deliver the cookie via a link, a cross-site request, or by exploiting another mechanism to set the cookie in the victim's browser. No authentication is required for the XSS to trigger once the cookie is present. [1]
Impact
Successful exploitation allows the attacker to execute arbitrary JavaScript in the victim's browser within the NPAM application's security context. This can lead to session hijacking, theft of sensitive data, or unauthorized actions on behalf of the victim user. [1]
Mitigation
The vulnerability is fixed in NetIQ Privileged Account Manager 3.1 Patch Update 3 (version 3.1.0.3). Users should upgrade to this version or later. No workarounds are documented in the available references. [1]
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <3.1 Patch Update 3
- Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- bugzilla.suse.com/show_bug.cgimitrex_refsource_CONFIRM
- www.netiq.com/documentation/privileged-account-manager-3/npam3103-release-notes/data/npam3103-release-notes.htmlmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.