IDM Identity Applications
by Microfocus
CVEs (2)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2016-1598 | Med | 0.35 | 5.4 | 0.01 | Oct 27, 2016 | XSS in NetIQ IDM 4.5 Identity Applications before 4.5.4 allows attackers able to change their username to inject arbitrary HTML code into the Role Assignment administrator HTML pages. | ||
| CVE-2017-9284 | Med | 0.31 | 4.8 | 0.01 | Apr 26, 2018 | IDM 4.6 Identity Applications prior to 4.6.2.1 may expose sensitive information. |
- risk 0.35cvss 5.4epss 0.01
XSS in NetIQ IDM 4.5 Identity Applications before 4.5.4 allows attackers able to change their username to inject arbitrary HTML code into the Role Assignment administrator HTML pages.
- risk 0.31cvss 4.8epss 0.01
IDM 4.6 Identity Applications prior to 4.6.2.1 may expose sensitive information.