Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
netiq vulnerabilities and exploits
(subscribe to this query)
7.2
CVSSv3
CVE-2017-9279
NetIQ Identity Manager prior to 4.5.6.1 allowed uploading files with double extensions or non-image content in the Themes handling of the User Application Administration, allowing malicious user administrators to potentially execute code or mislead users.
Netiq Identity Manager
7.5
CVSSv3
CVE-2017-9280
Some NetIQ Identity Manager Applications before Identity Manager 4.5.6.1 included the session token in GET URLs, potentially allowing exposure of user sessions to untrusted third parties via proxies, referer urls or similar.
Netiq Identity Manager
7.5
CVSSv3
CVE-2017-9284
IDM 4.6 Identity Applications before 4.6.2.1 may expose sensitive information.
Netiq Identity Manager
9.8
CVSSv3
CVE-2023-24468
Broken access control in Advanced Authentication versions before 6.4.1.1 and 6.3.7.2
Netiq Advanced Authentication
5.3
CVSSv3
CVE-2018-1350
The NetIQ Identity Manager driver log file, in versions before 4.7, provides details that could aid in system enumeration.
Netiq Identity Manager
7.4
CVSSv3
CVE-2018-1348
NetIQ Identity Manager driver, in versions before 4.7, allows for an SSL handshake renegotiation which could result in a MITM attack.
Netiq Identity Manager
5.3
CVSSv3
CVE-2018-1349
The NetIQ Identity Manager driver log file, in versions before 4.7, provides details that could aid in system or configuration enumeration.
Netiq Identity Manager
6.1
CVSSv3
CVE-2017-14800
A reflected cross site scripting attack in the NetIQ Access Manager prior to 4.3.3 using the "typecontainerid" parameter of the policy editor could allowed code injection into pages of authenticated users.
Netiq Access Manager
6.1
CVSSv3
CVE-2017-14801
Reflected XSS in the NetIQ Access Manager prior to 4.3.3 allowed malicious users to reflect back xss into the called page using the url parameter.
Netiq Access Manager
6.1
CVSSv3
CVE-2017-14799
A cross site scripting attack in handling the ESP login parameter handling in NetIQ Access Manager prior to 4.3.3 could be used to inject javascript code into the login page.
Netiq Access Manager
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2020-4463
CVE-2024-3400
deserialization
CVE-2024-21788
CVE-2023-42433
CVE-2024-21841
CVE-2024-22095
local file inclusion
memory leak
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
10
NEXT »