Multiple high risk vulnerabilities
Authenticated administrative users can download arbitrary files from the Access Manager administration interface as the user 'novlwww'. The download functionality is vulnerable to XML eXternal Entity Injection (XXE) attacks. An attacker can inject malicious XML code into the download request and gain access to arbitrary files on the server. The Access Manager administration interface is vulnerable to Cross-Site Request Forgery (CSRF) attacks. An attacker can perform administrative actions on the Access Manager without the knowledge of the administrator. The Access Manager administration interface is vulnerable to Cross-Site Scripting (XSS) attacks. An attacker can inject malicious JavaScript code into the administration interface and gain access to the session of an administrative user. The Access Manager administration interface discloses the full path of the application.