Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
netiq identity manager vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2022-26329
File existence disclosure vulnerability in NetIQ Identity Manager plugin prior to version 4.8.5 allows malicious user to determine whether a file exists on the filesystem. This issue affects: Micro Focus NetIQ Identity Manager NetIQ Identity Manager versions before 4.8.5 on ALL.
Netiq Identity Manager
9
CVSSv2
CVE-2017-9279
NetIQ Identity Manager prior to 4.5.6.1 allowed uploading files with double extensions or non-image content in the Themes handling of the User Application Administration, allowing malicious user administrators to potentially execute code or mislead users.
Netiq Identity Manager
5
CVSSv2
CVE-2017-9280
Some NetIQ Identity Manager Applications before Identity Manager 4.5.6.1 included the session token in GET URLs, potentially allowing exposure of user sessions to untrusted third parties via proxies, referer urls or similar.
Netiq Identity Manager
5
CVSSv2
CVE-2017-9284
IDM 4.6 Identity Applications before 4.6.2.1 may expose sensitive information.
Netiq Identity Manager
5
CVSSv2
CVE-2017-7434
In the JDBC driver of NetIQ Identity Manager prior to 4.6 sending out incorrect XML configurations could result in passwords being logged into exception logfiles.
Netiq Identity Manager
5.8
CVSSv2
CVE-2018-7674
The NetIQ Identity Manager user console, in versions before 4.7, is susceptible to URL redirection.
Netiq Identity Manager
4.3
CVSSv2
CVE-2016-1592
XSS in NetIQ Designer for Identity Manager prior to 4.5.3 allows remote malicious users to inject arbitrary HTML code via the nrfEntitlementReport.do CGI.
Netiq Identity Manager
5
CVSSv2
CVE-2017-9278
The NetIQ Identity Manager Oracle EBS driver prior to 4.0.2.0 sent EBS logs containing the driver authentication password, potentially disclosing this to attackers able to read the EBS tables.
Netiq Identity Manager
4.3
CVSSv2
CVE-2015-0787
XSS in NetIQ Designer for Identity Manager prior to 4.5.3 allows remote malicious users to inject arbitrary HTML code via the accessMgrDN value of the forgotUser.do CGI.
Netiq Identity Manager
6.4
CVSSv2
CVE-2017-7426
The NetIQ Identity Manager Plugins prior to 4.6.1 contained various XML External XML Entity (XXE) handling flaws that could be used by malicious users to leak information or cause denial of service attacks.
Netiq Identity Manager
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
path traversal
CVE-2024-33545
CVE-2024-35725
CVE-2024-32704
overflow
file upload
CVE-2024-0230
CVE-2024-32705
CVE-2024-23692
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
NEXT »