Netiq

Identity Manager

20 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.3%
  • Published 26.01.2023 21:15:32
  • Last modified 21.11.2024 06:53:45

File existence disclosure vulnerability in NetIQ Identity Manager plugin prior to version 4.8.5 allows attacker to determine whether a file exists on the filesystem. This issue affects: Micro Focus NetIQ Identity Manager NetIQ Identity Manager versio...

  • EPSS 0.29%
  • Published 26.04.2018 15:29:00
  • Last modified 21.11.2024 03:35:45

IDM 4.6 Identity Applications prior to 4.6.2.1 may expose sensitive information.

  • EPSS 0.29%
  • Published 28.03.2018 14:29:00
  • Last modified 21.11.2024 04:12:31

The NetIQ Identity Manager, in versions prior to 4.7, userapp with log / trace enabled may leak sensitive information.

  • EPSS 0.2%
  • Published 28.03.2018 14:29:00
  • Last modified 21.11.2024 04:12:30

The NetIQ Identity Manager user console, in versions prior to 4.7, is susceptible to URL redirection.

  • EPSS 0.17%
  • Published 26.03.2018 19:29:00
  • Last modified 21.11.2024 04:12:30

The NetIQ Identity Manager communication channel, in versions prior to 4.7, is susceptible to a DoS attack.

  • EPSS 0.16%
  • Published 26.03.2018 19:29:00
  • Last modified 21.11.2024 03:59:40

The NetIQ Identity Manager driver log file, in versions prior to 4.7, provides details that could aid in system enumeration.

  • EPSS 0.16%
  • Published 26.03.2018 19:29:00
  • Last modified 21.11.2024 03:59:40

The NetIQ Identity Manager driver log file, in versions prior to 4.7, provides details that could aid in system or configuration enumeration.

  • EPSS 0.21%
  • Published 26.03.2018 19:29:00
  • Last modified 21.11.2024 03:59:40

NetIQ Identity Manager driver, in versions prior to 4.7, allows for an SSL handshake renegotiation which could result in a MITM attack.

  • EPSS 0.2%
  • Published 05.03.2018 16:29:00
  • Last modified 21.11.2024 03:31:52

Multiple cross site scripting attacks were found in the Identity Manager Plug-in, hosted on iManager 2.7.7.7, before Identity Manager 4.6.1. In certain scenarios it was possible to execute arbitrary JavaScript code in the context of vulnerable applic...

  • EPSS 0.2%
  • Published 02.03.2018 20:29:00
  • Last modified 21.11.2024 03:35:44

Some NetIQ Identity Manager Applications before Identity Manager 4.5.6.1 included the session token in GET URLs, potentially allowing exposure of user sessions to untrusted third parties via proxies, referer urls or similar.