Vulnerable Systems:
* Portwise SSL VPN version 4.6
Other versions may be also affected
An attacker may be able to cause execution of malicious scripting code in the browser of a user who clicks on a link to a Portwise Portal-based site. Such code would run within the security context of the target domain. This type of attack can result in non-persistent defacement of the target site, or the redirection of confidential information (i.e.: session IDs) to unauthorised third parties.
In order to recreate the issue, access the Login page using the following parameters: