Netiq

Access Manager

24 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.46%
  • Published 20.01.2018 00:29:00
  • Last modified 21.11.2024 03:13:32

In NetIQ Access Manager 4.3 and 4.4, a bug exists in Identity Server when accessing a basic SSO connector and downloading the BasicSSO connector plugins on IE11 where an attacker can execute arbitrary code on the system.

  • EPSS 0.24%
  • Published 24.04.2017 18:59:00
  • Last modified 20.04.2025 01:37:25

An XSS vulnerability on the /NAGErrors URI in NetIQ Access Manager 4.2 and 4.3 exists because Access Gateway Error pages do not validate the HTTP Referer header.

  • EPSS 0.24%
  • Published 20.04.2017 18:59:01
  • Last modified 20.04.2025 01:37:25

NetIQ Access Manager 4.2.2 and 4.3.x before 4.3.1+, when configured as an Identity Server, has XSS in the AssertionConsumerServiceURL field of a signed AuthnRequest in a samlp:AuthnRequest document.

  • EPSS 0.24%
  • Published 20.04.2017 15:59:00
  • Last modified 20.04.2025 01:37:25

NetIQ Access Manager 4.2 before SP3 HF1 and 4.3 before SP1 HF1, when configured as a SAML 2.0 Identity Server with Virtual Attributes, has a concurrency issue causing information leakage, related to a stale profile.

  • EPSS 0.05%
  • Published 23.03.2017 06:59:00
  • Last modified 20.04.2025 01:37:25

External Entity Processing (XXE) vulnerability in the "risk score" application of NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 could be used to disclose the content of local files to logged-in users.

  • EPSS 0.14%
  • Published 23.03.2017 06:59:00
  • Last modified 20.04.2025 01:37:25

A cross site request forgery protection mechanism in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 could be circumvented by repeated uploads causing a high load.

  • EPSS 1.07%
  • Published 23.03.2017 06:59:00
  • Last modified 20.04.2025 01:37:25

iManager Admin Console in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 was vulnerable to iFrame manipulation attacks, which could allow remote users to gain access to authentication credentials.

  • EPSS 0.24%
  • Published 23.03.2017 06:59:00
  • Last modified 20.04.2025 01:37:25

Multiple components of the web tools in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 were vulnerable to Reflected Cross Site Scripting attacks which could be used to hijack user sessions: nps/servlet/frameservice, nps/servlet/...

  • EPSS 0.13%
  • Published 23.03.2017 06:59:00
  • Last modified 20.04.2025 01:37:25

NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 was vulnerable to clickjacking attacks due to a missing SAMEORIGIN filter in the "high encryption" setting.

  • EPSS 0.3%
  • Published 23.03.2017 06:59:00
  • Last modified 20.04.2025 01:37:25

Presence of a .htaccess file could leak information in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before SP2.