Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
netiq vulnerabilities and exploits
(subscribe to this query)
6.1
CVSSv3
CVE-2015-0787
XSS in NetIQ Designer for Identity Manager prior to 4.5.3 allows remote malicious users to inject arbitrary HTML code via the accessMgrDN value of the forgotUser.do CGI.
Netiq Identity Manager
6.1
CVSSv3
CVE-2016-1592
XSS in NetIQ Designer for Identity Manager prior to 4.5.3 allows remote malicious users to inject arbitrary HTML code via the nrfEntitlementReport.do CGI.
Netiq Identity Manager
6.1
CVSSv3
CVE-2016-1599
Cross-site scripting (XSS) vulnerability in NetIQ Self Service Password Reset (SSPR) 2.x and 3.x prior to 3.3.1 HF2 allows remote malicious users to inject arbitrary web script or HTML via a crafted URL.
Microfocus Self Service Password Reset 3.0
Microfocus Self Service Password Reset 2.0
Microfocus Self Service Password Reset 3.1
Microfocus Self Service Password Reset 3.3
Microfocus Self Service Password Reset 3.3.1
Microfocus Self Service Password Reset 3.2
5.9
CVSSv3
CVE-2019-11674
Man-in-the-middle vulnerability in Micro Focus Self Service Password Reset, affecting all versions before 4.4.0.4. The vulnerability could exploit invalid certificate validation and may result in a man-in-the-middle attack.
Microfocus Netiq Self Service Password Reset
Microfocus Netiq Self Service Password Reset 4.4
5.9
CVSSv3
CVE-2019-11650
A potential Man in the Middle attack (MITM) was found in NetIQ Advanced Authentication Framework versions before 6.0.
Microfocus Netiq Advanced Authentication
5.9
CVSSv3
CVE-2018-7676
The NetIQ Identity Manager, in versions before 4.7, userapp with log / trace enabled may leak sensitive information.
Netiq Identity Manager
5.5
CVSSv3
CVE-2021-22525
This release addresses a potential information leakage vulnerability in NetIQ Access Manager versions before 5.0.1
Microfocus Access Manager
5.5
CVSSv3
CVE-2016-5749
NetIQ Access Manager 4.1 prior to 4.1.2 HF 1 and 4.2 prior to 4.2.2 was parsing incoming SAML requests with external entity resolution enabled, which could lead to local file disclosure via an XML External Entity (XXE) attack.
Netiq Access Manager 4.1
Netiq Access Manager 4.2
5.5
CVSSv3
CVE-2016-5748
External Entity Processing (XXE) vulnerability in the "risk score" application of NetIQ Access Manager 4.1 prior to 4.1.2 Hot Fix 1 and 4.2 prior to 4.2.2 could be used to disclose the content of local files to logged-in users.
Netiq Access Manager 4.1
Netiq Access Manager 4.2
5.4
CVSSv3
CVE-2021-22528
Reflected Cross Site Scripting (XSS) vulnerability in NetIQ Access Manager before 5.0.1 and 4.5.4
Microfocus Access Manager
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
SSTI
CVE-2024-35863
CVE-2024-35910
man-in-the-middle
CVE-2024-35912
CVE-2024-25742
LFI
CVE-2024-32002
CVE-2024-22120
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
3
4
5
6
7
8
9
10
NEXT »