AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2016-5756

MEDIUM · CVSS 6.1 EPSS 0.64%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2017-03-23 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 6.1. See the original NVD description below for full technical details.

CVE
CVE-2016-5756
Severity
MEDIUM
CVSS
6.1
EPSS
0.64%

Original NVD Description

Multiple components of the web tools in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 were vulnerable to Reflected Cross Site Scripting attacks which could be used to hijack user sessions: nps/servlet/frameservice, nps/servlet/webacc, roma/admin/cntl, roma/jsp/admin/appliance/devicedetail_edit.jsp, roma/jsp/admin/managementip/mgmt_ip_details_frameset.jsp, roma/jsp/admin/managementip/mgmt_ip_details_middleframe.jsp, roma/jsp/volsc/monitoring/appliance.jsp, and roma/jsp/volsc/monitoring/graph.jsp.

Related CVEs

Other vulnerabilities affecting the same vendor(s)