Vulnerabilities (CVE)

Filtered by vendor Netiq Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-7429 2 Microfocus, Netiq 2 Edirectory, Edirectory 2021-04-13 6.5 MEDIUM 8.8 HIGH
The certificate upload in NetIQ eDirectory PKI plugin before 8.8.8 Patch 10 Hotfix 1 could be abused to upload JSP code which could be used by authenticated attackers to execute JSP applets on the iManager server.
CVE-2018-7677 1 Netiq 1 Access Manager 2019-10-09 6.8 MEDIUM 8.8 HIGH
A CSRF exposure exists in NetIQ Access Manager (NAM) 4.4 Identity Server component.
CVE-2018-7673 1 Netiq 1 Identity Manager 2019-10-09 5.0 MEDIUM 7.5 HIGH
The NetIQ Identity Manager communication channel, in versions prior to 4.7, is susceptible to a DoS attack.
CVE-2018-1348 1 Netiq 1 Identity Manager 2019-10-09 5.8 MEDIUM 7.4 HIGH
NetIQ Identity Manager driver, in versions prior to 4.7, allows for an SSL handshake renegotiation which could result in a MITM attack.
CVE-2018-1346 1 Netiq 1 Edirectory 2019-10-09 5.0 MEDIUM 7.5 HIGH
Addresses denial of service attack to eDirectory versions prior to 9.1.
CVE-2018-1344 1 Netiq 1 Imanager 2019-10-09 5.0 MEDIUM 8.6 HIGH
Addresses potential communication downgrade attack in NetIQ iManager versions prior to 3.1
CVE-2018-1345 1 Netiq 1 Imanager 2019-10-09 6.5 MEDIUM 8.8 HIGH
NetIQ iManager, versions prior to 3.1, under some circumstances could be susceptible to an elevation of privilege attack.
CVE-2018-12461 1 Netiq 1 Edirectory 2019-10-09 5.0 MEDIUM 7.5 HIGH
Fixed issues with NetIQ eDirectory prior to 9.1.1 when checking certificate revocation.
CVE-2017-9279 1 Netiq 1 Identity Manager 2019-10-09 9.0 HIGH 7.2 HIGH
NetIQ Identity Manager before 4.5.6.1 allowed uploading files with double extensions or non-image content in the Themes handling of the User Application Administration, allowing malicious user administrators to potentially execute code or mislead users.
CVE-2017-9280 1 Netiq 1 Identity Manager 2019-10-09 5.0 MEDIUM 7.5 HIGH
Some NetIQ Identity Manager Applications before Identity Manager 4.5.6.1 included the session token in GET URLs, potentially allowing exposure of user sessions to untrusted third parties via proxies, referer urls or similar.
CVE-2017-9284 1 Netiq 1 Identity Manager 2019-10-09 5.0 MEDIUM 7.5 HIGH
IDM 4.6 Identity Applications prior to 4.6.2.1 may expose sensitive information.
CVE-2017-5189 1 Netiq 1 Imanager 2019-10-09 5.0 MEDIUM 7.5 HIGH
NetIQ iManager before 3.0.3 delivered a SSL private key in a Java application (JAR file) for authentication to Sentinel, allowing attackers to extract and establish their own connections to the Sentinel appliance.
CVE-2017-5186 2 Netiq, Novell 4 Edirectory, Imanager, Edirectory and 1 more 2019-10-03 4.3 MEDIUM 7.5 HIGH
Novell iManager 2.7 before SP7 Patch 9, NetIQ iManager 3.x before 3.0.2.1, Novell eDirectory 8.8.x before 8.8 SP8 Patch 9 Hotfix 2, and NetIQ eDirectory 9.x before 9.0.2 Hotfix 2 (9.0.2.2) use the deprecated MD5 hashing algorithm in a communications certificate.
CVE-2019-11648 1 Netiq 1 Self Service Password Reset 2019-06-24 5.0 MEDIUM 7.5 HIGH
An information leakage exists in Micro Focus NetIQ Self Service Password Reset Software all versions prior to version 4.4. The vulnerability could be exploited to expose sensitive information.
CVE-2016-5758 1 Netiq 1 Access Manager 2019-04-23 6.8 MEDIUM 8.8 HIGH
A cross site request forgery protection mechanism in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 could be circumvented by repeated uploads causing a high load.
CVE-2017-7431 2 Netiq, Novell 2 Imanager, Imanager 2017-05-15 6.8 MEDIUM 8.8 HIGH
Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have persistent CSRF in object management.
CVE-2016-5752 1 Netiq 1 Access Manager 2017-03-24 5.0 MEDIUM 7.5 HIGH
The SAML2 implementation in Identity Server in NetIQ Access Manager 4.1 before 4.1.2 HF1 and 4.2 before 4.2.2 was handling unsigned SAML requests incorrectly, leaking results to a potentially malicious "Assertion Consumer Service URL" instead of the original requester.
CVE-2016-5750 1 Netiq 1 Access Manager 2017-03-24 6.5 MEDIUM 8.8 HIGH
The certificate upload feature in iManager in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 could be used to upload JSP pages that would be executed as the iManager user, allowing code execution by logged-in remote users.
CVE-2016-1597 1 Netiq 1 Access Governance Suite 2017-03-24 9.0 HIGH 8.8 HIGH
A logged-in user in NetIQ Access Governance Suite 6.0 through 6.4 could escalate privileges to administrator.
CVE-2016-5754 1 Netiq 1 Access Manager 2017-03-24 5.0 MEDIUM 7.5 HIGH
Presence of a .htaccess file could leak information in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before SP2.