Loading
Some NetIQ Identity Manager Applications before Identity Manager 4.5.6.1 included the session token in GET URLs, potentially allowing exposure of user sessions to untrusted third parties via proxies, referer urls or similar.
Use CWE-598, Netiq vendor hub and Identity Manager product page to widen CVE-2017-9280 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2017-7427, CVE-2018-1348 and CVE-2018-7673 for nearby disclosures in the same product family.