API's data during scope creation is not getting validated due to XSS (CVE-2019-11659)

  • 7024155
  • 01-Oct-2019
  • 03-Oct-2019

Environment

Access Manager 4.5


Situation

This addresses XSS vulnerabilities in the Access Manager Identity Provider product during scope creation using API.

Resolution

Fixed in 4.5.1

Status

Security Alert