← Vulnerability feed

Vulnerability record · CVE-2018-1347 · published 21 March 2018

CVE-2018-1347: Netiq imanager cross-site scripting vulnerability

Netiq · Imanager

The administrative web interface in NetIQ iManager, versions prior to 3.1, are vulnerable to reflected cross site scripting.

6.1 CVSS 3.0 Medium EPSS 0.73% · top 47.6% CWE-79 · Cross-site scripting
6.1CVSS 3.0 base score, v2 4.3
0.73%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

The administrative web interface in NetIQ iManager, versions prior to 3.1, are vulnerable to reflected cross site scripting.

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-1347 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-7432Novell imanager vulnerabilityNovell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have a webshell upload vulnerability.EPSS 1.5%8.8CVE-2018-1345Netiq imanager vulnerabilityNetIQ iManager, versions prior to 3.1, under some circumstances could be susceptible to an elevation of privilege attack.EPSS 0.65%8.8CVE-2017-7431Novell imanager cross-site request forgery vulnerabilityNovell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have persistent CSRF in object management.EPSS 0.58%8.6CVE-2018-1344Netiq imanager vulnerabilityAddresses potential communication downgrade attack in NetIQ iManager versions prior to 3.1EPSS 0.86%7.5CVE-2017-5189Netiq imanager insufficiently protected credentials vulnerabilityNetIQ iManager before 3.0.3 delivered a SSL private key in a Java application (JAR file) for authentication to Sentinel, allowing attackers to extrac…EPSS 1.2%7.5CVE-2017-5186Netiq edirectory broken cryptographic algorithm vulnerabilityNovell iManager 2.7 before SP7 Patch 9, NetIQ iManager 3.x before 3.0.2.1, Novell eDirectory 8.8.x before 8.8 SP8 Patch 9 Hotfix 2, and NetIQ eDirect…EPSS 0.65%6.1CVE-2022-38758Netiq imanager cross-site scripting vulnerabilityCross-site Scripting (XSS) vulnerability in NetIQ iManager prior to version 3.2.6 allows attacker to execute malicious scripts on the user's browser.…EPSS 0.45%6.1CVE-2018-12462Netiq imanager cross-site scripting vulnerabilityNetIQ iManager 3.1.1 addresses potential XSS vulnerabilities.EPSS 0.58%

Source: NIST National Vulnerability Database (record CVE-2018-1347), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.