Vulnerabilities (CVE)

Filtered by vendor Netiq Subscribe
Filtered by product Access Manager
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-7677 1 Netiq 1 Access Manager 2019-10-09 6.8 MEDIUM 8.8 HIGH
A CSRF exposure exists in NetIQ Access Manager (NAM) 4.4 Identity Server component.
CVE-2016-5758 1 Netiq 1 Access Manager 2019-04-23 6.8 MEDIUM 8.8 HIGH
A cross site request forgery protection mechanism in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 could be circumvented by repeated uploads causing a high load.
CVE-2016-5752 1 Netiq 1 Access Manager 2017-03-24 5.0 MEDIUM 7.5 HIGH
The SAML2 implementation in Identity Server in NetIQ Access Manager 4.1 before 4.1.2 HF1 and 4.2 before 4.2.2 was handling unsigned SAML requests incorrectly, leaking results to a potentially malicious "Assertion Consumer Service URL" instead of the original requester.
CVE-2016-5750 1 Netiq 1 Access Manager 2017-03-24 6.5 MEDIUM 8.8 HIGH
The certificate upload feature in iManager in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 could be used to upload JSP pages that would be executed as the iManager user, allowing code execution by logged-in remote users.
CVE-2016-5754 1 Netiq 1 Access Manager 2017-03-24 5.0 MEDIUM 7.5 HIGH
Presence of a .htaccess file could leak information in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before SP2.