Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
netiq vulnerabilities and exploits
(subscribe to this query)
605
VMScore
CVE-2015-0795
Multiple stack-based buffer overflows in the SafeShellExecute method in the NetIQExecObject.NetIQExec.1 ActiveX control in NetIQExec.dll in NetIQ Security Solutions for iSeries 8.1 allow remote malicious users to execute arbitrary code via long arguments, aka ZDI-CAN-2699.
Microfocus Security Solutions For Iseries 8.1
605
VMScore
CVE-2014-5217
Cross-site request forgery (CSRF) vulnerability in nps/servlet/webacc in the Administration Console server in NetIQ Access Manager (NAM) 4.x prior to 4.1 allows remote malicious users to hijack the authentication of administrators for requests that change the administrative passw...
Microfocus Access Manager 4.0.1
Microfocus Access Manager 4.0
605
VMScore
CVE-2014-3460
Directory traversal vulnerability in the DumpToFile method in the NQMcsVarSet ActiveX control in Agent Manager in NetIQ Sentinel allows remote malicious users to create arbitrary files, and consequently execute arbitrary code, via a crafted pathname.
Microfocus Sentinel -
Microfocus Sentinel Agent Manager -
578
VMScore
CVE-2021-22497
Advanced Authentication versions before 6.3 SP4 have a potential broken authentication due to improper session management issue.
Microfocus Netiq Advanced Authentication 6.3
Microfocus Netiq Advanced Authentication
578
VMScore
CVE-2018-1345
NetIQ iManager, versions before 3.1, under some circumstances could be susceptible to an elevation of privilege attack.
Netiq Imanager
578
VMScore
CVE-2017-7429
The certificate upload in NetIQ eDirectory PKI plugin prior to 8.8.8 Patch 10 Hotfix 1 could be abused to upload JSP code which could be used by authenticated malicious users to execute JSP applets on the iManager server.
Netiq Edirectory 8.8.8
Microfocus Edirectory
578
VMScore
CVE-2016-5750
The certificate upload feature in iManager in NetIQ Access Manager 4.1 prior to 4.1.2 Hot Fix 1 and 4.2 prior to 4.2.2 could be used to upload JSP pages that would be executed as the iManager user, allowing code execution by logged-in remote users.
Netiq Access Manager 4.1
Netiq Access Manager 4.2
570
VMScore
CVE-2017-7426
The NetIQ Identity Manager Plugins prior to 4.6.1 contained various XML External XML Entity (XXE) handling flaws that could be used by malicious users to leak information or cause denial of service attacks.
Netiq Identity Manager
570
VMScore
CVE-2012-0430
Unspecified vulnerability in NetIQ eDirectory 8.8.6.x prior to 8.8.6.7 and 8.8.7.x prior to 8.8.7.2 on Windows allows remote malicious users to obtain an administrator cookie and bypass authorization checks via unknown vectors.
Microfocus Edirectory 8.8.6.0
Microfocus Edirectory 8.8.6.6
Microfocus Edirectory 8.8.6.5
Microfocus Edirectory 8.8.6.2
Microfocus Edirectory 8.8.6.1
Microfocus Edirectory 8.8.6.4
Microfocus Edirectory 8.8.6.3
Microfocus Edirectory 8.8.7.0
Microfocus Edirectory 8.8.7.1
555
VMScore
CVE-2012-5931
Directory traversal vulnerability in the set_log_config function in regclnt.dll in unifid.exe in NetIQ Privileged User Manager 2.3.x prior to 2.3.1 HF2 allows remote authenticated users to create or overwrite arbitrary files via directory traversal sequences in a log pathname.
Microfocus Privileged User Manager 2.3.1
Microfocus Privileged User Manager 2.3.0
1 EDB exploit
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2020-4463
CVE-2024-3400
deserialization
CVE-2024-21788
CVE-2023-42433
CVE-2024-21841
CVE-2024-22095
local file inclusion
memory leak
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
NEXT »