CVE-2025-65431
- EPSS 0.03%
- Veröffentlicht 15.12.2025 00:00:00
- Zuletzt bearbeitet 23.12.2025 18:08:38
An issue was discovered in allauth-django before 65.13.0. Both Okta and NetIQ were using preferred_username as the identifier for third-party provider accounts. That value may be mutable and should therefore be avoided for authorization decisions. Th...
CVE-2022-26329
- EPSS 0.23%
- Veröffentlicht 26.01.2023 21:15:32
- Zuletzt bearbeitet 21.11.2024 06:53:45
File existence disclosure vulnerability in NetIQ Identity Manager plugin prior to version 4.8.5 allows attacker to determine whether a file exists on the filesystem. This issue affects: Micro Focus NetIQ Identity Manager NetIQ Identity Manager versio...
CVE-2017-9284
- EPSS 0.28%
- Veröffentlicht 26.04.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:35:45
IDM 4.6 Identity Applications prior to 4.6.2.1 may expose sensitive information.
CVE-2018-7676
- EPSS 0.28%
- Veröffentlicht 28.03.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 04:12:31
The NetIQ Identity Manager, in versions prior to 4.7, userapp with log / trace enabled may leak sensitive information.
CVE-2018-7674
- EPSS 0.2%
- Veröffentlicht 28.03.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 04:12:30
The NetIQ Identity Manager user console, in versions prior to 4.7, is susceptible to URL redirection.
CVE-2018-7673
- EPSS 0.17%
- Veröffentlicht 26.03.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 04:12:30
The NetIQ Identity Manager communication channel, in versions prior to 4.7, is susceptible to a DoS attack.
CVE-2018-1350
- EPSS 0.16%
- Veröffentlicht 26.03.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:40
The NetIQ Identity Manager driver log file, in versions prior to 4.7, provides details that could aid in system enumeration.
CVE-2018-1349
- EPSS 0.16%
- Veröffentlicht 26.03.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:40
The NetIQ Identity Manager driver log file, in versions prior to 4.7, provides details that could aid in system or configuration enumeration.
CVE-2018-1348
- EPSS 0.2%
- Veröffentlicht 26.03.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:40
NetIQ Identity Manager driver, in versions prior to 4.7, allows for an SSL handshake renegotiation which could result in a MITM attack.
CVE-2017-7427
- EPSS 0.2%
- Veröffentlicht 05.03.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:31:52
Multiple cross site scripting attacks were found in the Identity Manager Plug-in, hosted on iManager 2.7.7.7, before Identity Manager 4.6.1. In certain scenarios it was possible to execute arbitrary JavaScript code in the context of vulnerable applic...