Vulnerabilities (CVE)

Filtered by vendor Netiq Subscribe
Filtered by product Identity Manager
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-4506 1 Netiq 1 Identity Manager 2018-09-27 3.6 LOW N/A
idmlib.sh in nxdrv in Novell Identity Manager (IDM) 3.0.1 allows local users to execute arbitrary commands via unspecified vectors, possibly involving the " (quote) and \ (backslash) characters and eval injection.
CVE-2006-4803 1 Netiq 1 Identity Manager 2018-09-27 7.2 HIGH N/A
The Fan-Out Linux and UNIX receiver scripts in Novell Identity Manager (IDM) 3.0.1 allows local users to execute arbitrary commands via unspecified vectors involving certain environment variables and "code injection."
CVE-2007-4526 2 Netiq, Novell 2 Identity Manager, Client Login Extension \(cle\) 2018-09-27 2.1 LOW N/A
The Client Login Extension (CLE) in Novell Identity Manager before 3.5.1 20070730 stores the username and password in a local file, which allows local users to obtain sensitive information by reading this file.
CVE-2014-4509 1 Netiq 1 Identity Manager 2018-09-27 4.6 MEDIUM N/A
The MKDQUOTESAFE function in the Fan-out driver scripts in Fan-Out Platform Services in Novell Identity Manager (aka IDM) 4.0.2 allows local users to execute arbitrary commands by leveraging eDirectory POSIX attribute changes to insert shell metacharacters.