Netiq

Identity Manager

21 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.03%
  • Veröffentlicht 15.12.2025 00:00:00
  • Zuletzt bearbeitet 23.12.2025 18:08:38

An issue was discovered in allauth-django before 65.13.0. Both Okta and NetIQ were using preferred_username as the identifier for third-party provider accounts. That value may be mutable and should therefore be avoided for authorization decisions. Th...

  • EPSS 0.23%
  • Veröffentlicht 26.01.2023 21:15:32
  • Zuletzt bearbeitet 21.11.2024 06:53:45

File existence disclosure vulnerability in NetIQ Identity Manager plugin prior to version 4.8.5 allows attacker to determine whether a file exists on the filesystem. This issue affects: Micro Focus NetIQ Identity Manager NetIQ Identity Manager versio...

  • EPSS 0.28%
  • Veröffentlicht 26.04.2018 15:29:00
  • Zuletzt bearbeitet 21.11.2024 03:35:45

IDM 4.6 Identity Applications prior to 4.6.2.1 may expose sensitive information.

  • EPSS 0.28%
  • Veröffentlicht 28.03.2018 14:29:00
  • Zuletzt bearbeitet 21.11.2024 04:12:31

The NetIQ Identity Manager, in versions prior to 4.7, userapp with log / trace enabled may leak sensitive information.

  • EPSS 0.2%
  • Veröffentlicht 28.03.2018 14:29:00
  • Zuletzt bearbeitet 21.11.2024 04:12:30

The NetIQ Identity Manager user console, in versions prior to 4.7, is susceptible to URL redirection.

  • EPSS 0.17%
  • Veröffentlicht 26.03.2018 19:29:00
  • Zuletzt bearbeitet 21.11.2024 04:12:30

The NetIQ Identity Manager communication channel, in versions prior to 4.7, is susceptible to a DoS attack.

  • EPSS 0.16%
  • Veröffentlicht 26.03.2018 19:29:00
  • Zuletzt bearbeitet 21.11.2024 03:59:40

The NetIQ Identity Manager driver log file, in versions prior to 4.7, provides details that could aid in system enumeration.

  • EPSS 0.16%
  • Veröffentlicht 26.03.2018 19:29:00
  • Zuletzt bearbeitet 21.11.2024 03:59:40

The NetIQ Identity Manager driver log file, in versions prior to 4.7, provides details that could aid in system or configuration enumeration.

  • EPSS 0.2%
  • Veröffentlicht 26.03.2018 19:29:00
  • Zuletzt bearbeitet 21.11.2024 03:59:40

NetIQ Identity Manager driver, in versions prior to 4.7, allows for an SSL handshake renegotiation which could result in a MITM attack.

  • EPSS 0.2%
  • Veröffentlicht 05.03.2018 16:29:00
  • Zuletzt bearbeitet 21.11.2024 03:31:52

Multiple cross site scripting attacks were found in the Identity Manager Plug-in, hosted on iManager 2.7.7.7, before Identity Manager 4.6.1. In certain scenarios it was possible to execute arbitrary JavaScript code in the context of vulnerable applic...