Loading
NetIQ Access Manager 4.2.2 and 4.3.x before 4.3.1+, when configured as an Identity Server, has XSS in the AssertionConsumerServiceURL field of a signed AuthnRequest in a samlp:AuthnRequest document.
Use CWE-79, Netiq vendor hub and Access Manager product page to widen CVE-2017-5183 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2018-1342, CVE-2017-14803 and CVE-2020-11843 for nearby disclosures in the same product family.