- EPSS 1.46%
- Veröffentlicht 20.01.2018 00:29:00
- Zuletzt bearbeitet 21.11.2024 03:13:32
In NetIQ Access Manager 4.3 and 4.4, a bug exists in Identity Server when accessing a basic SSO connector and downloading the BasicSSO connector plugins on IE11 where an attacker can execute arbitrary code on the system.
CVE-2017-5191
- EPSS 0.24%
- Veröffentlicht 24.04.2017 18:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
An XSS vulnerability on the /NAGErrors URI in NetIQ Access Manager 4.2 and 4.3 exists because Access Gateway Error pages do not validate the HTTP Referer header.
CVE-2017-5183
- EPSS 0.24%
- Veröffentlicht 20.04.2017 18:59:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
NetIQ Access Manager 4.2.2 and 4.3.x before 4.3.1+, when configured as an Identity Server, has XSS in the AssertionConsumerServiceURL field of a signed AuthnRequest in a samlp:AuthnRequest document.
CVE-2017-5190
- EPSS 0.24%
- Veröffentlicht 20.04.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
NetIQ Access Manager 4.2 before SP3 HF1 and 4.3 before SP1 HF1, when configured as a SAML 2.0 Identity Server with Virtual Attributes, has a concurrency issue causing information leakage, related to a stale profile.
CVE-2016-5748
- EPSS 0.05%
- Veröffentlicht 23.03.2017 06:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
External Entity Processing (XXE) vulnerability in the "risk score" application of NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 could be used to disclose the content of local files to logged-in users.
CVE-2016-5758
- EPSS 0.14%
- Veröffentlicht 23.03.2017 06:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
A cross site request forgery protection mechanism in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 could be circumvented by repeated uploads causing a high load.
CVE-2016-5757
- EPSS 1.07%
- Veröffentlicht 23.03.2017 06:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
iManager Admin Console in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 was vulnerable to iFrame manipulation attacks, which could allow remote users to gain access to authentication credentials.
CVE-2016-5756
- EPSS 0.24%
- Veröffentlicht 23.03.2017 06:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Multiple components of the web tools in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 were vulnerable to Reflected Cross Site Scripting attacks which could be used to hijack user sessions: nps/servlet/frameservice, nps/servlet/...
CVE-2016-5755
- EPSS 0.13%
- Veröffentlicht 23.03.2017 06:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 was vulnerable to clickjacking attacks due to a missing SAMEORIGIN filter in the "high encryption" setting.
CVE-2016-5754
- EPSS 0.3%
- Veröffentlicht 23.03.2017 06:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Presence of a .htaccess file could leak information in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before SP2.