CVE-2016-1598
Estado: ModificadaMedia (5.4)—
XSS in NetIQ IDM 4.5 Identity Applications before 4.5.4 allows attackers able to change their username to inject arbitrary HTML code into the Role Assignment administrator HTML pages.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- Puntuación base: 5.4
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.56%
- Percentil entre todas las CVEs puntuadas: 45
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-79
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2016-1598",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 3.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:S/C:N/I:P/A:N",
"authentication": "SINGLE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 6.8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.0",
"baseScore": 5.4,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 2.3
}
]
},
"affected": [
{
"source": "security@opentext.com",
"affectedData": [
{
"vendor": "n/a",
"product": "NetIQ IDM 4.5 Identity Applications before 4.5.4",
"versions": [
{
"status": "affected",
"version": "NetIQ IDM 4.5 Identity Applications before 4.5.4"
}
]
}
]
}
],
"published": "2016-10-27T20:59:04.243",
"references": [
{
"url": "http://www.securityfocus.com/bid/93833",
"source": "security@opentext.com"
},
{
"url": "https://download.novell.com/Download?buildid=xyswDCMsT7I~",
"source": "security@opentext.com"
},
{
"url": "http://www.securityfocus.com/bid/93833",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://download.novell.com/Download?buildid=xyswDCMsT7I~",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "XSS in NetIQ IDM 4.5 Identity Applications before 4.5.4 allows attackers able to change their username to inject arbitrary HTML code into the Role Assignment administrator HTML pages."
},
{
"lang": "es",
"value": "XSS en NetIQ IDM 4.5 Identity Applications en versiones anteriores a 4.5.4 permite a los atacantes capaces de cambiar su nombre de usuario inyectar un código HTML arbitrario dentro de las páginas HTML de administrador Role Assignment."
}
],
"lastModified": "2026-06-17T00:42:14.040",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:novell:identity_manager:4.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9086558A-4088-4EA5-BCDE-1F7ED3D4F60A"
},
{
"criteria": "cpe:2.3:a:novell:identity_manager_identity_applications:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "184E8AEA-2726-4472-93AB-3135714FC550",
"versionEndIncluding": "4.5.3"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@opentext.com"
}