4
CVSSv2

CVE-2014-5215

Published: 23/12/2014 Updated: 09/04/2021
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

NetIQ Access Manager (NAM) 4.x prior to 4.0.1 HF3 allows remote authenticated administrators to discover service-account passwords via a request to (1) roma/jsp/volsc/monitoring/dev_services.jsp or (2) roma/jsp/debug/debug.jsp.

Vulnerable Product Search on Vulmon Subscribe to Product

microfocus access manager 4.0.1

microfocus access manager 4.0

Exploits

NetIQ Access Manager version 40 SP1 suffers from cross site request forgery, external entity injection, information disclosure, and cross site scripting vulnerabilities ...