ZeroHour

CVE-2017-9280

CVSS 3.0
7.5 high
EPSS
1%p64
Published
()
Modified
Description

Some NetIQ Identity Manager Applications before Identity Manager 4.5.6.1 included the session token in GET URLs, potentially allowing exposure of user sessions to untrusted third parties via proxies, referer urls or similar.

Vendors
netiq
Products
identity manager
Weakness
CWE-598, CWE-200
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.