CVE-2018-0908

Microsoft Identity Manager 2016 SP1 allows an attacker to gain elevated privileges when it does not properly sanitize a specially crafted attribute value being displayed to a user on an affected MIM 2016 server, aka "Microsoft Identity Manager XSS Elevation of Privilege Vulnerability."
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:microsoft:identity_manager:2016:sp1:*:*:*:*:*:*

History

No history.

Information

Published : 2018-02-26 22:29

Updated : 2024-02-04 19:46


NVD link : CVE-2018-0908

Mitre link : CVE-2018-0908

CVE.ORG link : CVE-2018-0908


JSON object : View

Products Affected

microsoft

  • identity_manager
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')