7.5

CVE-2017-5189

private SSL key embedded in JAR file in iManager

NetIQ iManager before 3.0.3 delivered a SSL private key in a Java application (JAR file) for authentication to Sentinel, allowing attackers to extract and establish their own connections to the Sentinel appliance.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Netiq ≫ Imanager Version 2.7
Netiq ≫ Imanager Version 2.7.1
Netiq ≫ Imanager Version 2.7.2
Netiq ≫ Imanager Version 2.7.3
Netiq ≫ Imanager Version 2.7.4
Netiq ≫ Imanager Version 2.7.5
Netiq ≫ Imanager Version 2.7.6
Netiq ≫ Imanager Version 2.7.7 Update p10
Netiq ≫ Imanager Version 2.7.7 Update p11
Netiq ≫ Imanager Version 2.7.7 Update p4
Netiq ≫ Imanager Version 2.7.7 Update p5
Netiq ≫ Imanager Version 2.7.7 Update p6
Netiq ≫ Imanager Version 2.7.7 Update p7
Netiq ≫ Imanager Version 2.7.7 Update p8
Netiq ≫ Imanager Version 2.7.7 Update p9
Netiq ≫ Imanager Version 2.7.7.10 Update hf1
Netiq ≫ Imanager Version 2.7.7.10 Update hf2
Netiq ≫ Imanager Version 3.0
Netiq ≫ Imanager Version 3.0 Update sp1
Netiq ≫ Imanager Version 3.0 Update sp2
Netiq ≫ Imanager Version 3.0 Update sp3
Netiq ≫ Imanager Version 3.0 Update sp4
Netiq ≫ Imanager Version 3.0.2 Update p1
Netiq ≫ Imanager Version 3.0.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.17% 0.644
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
OpenText 4.3 2.8 1.4
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

CWE-522 Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

https://www.netiq.com/support/kb/doc.php?id=7016795
https://bugzilla.suse.com/show_bug.cgi?id=1021637