6.8
CVSSv2

CVE-2014-5217

Published: 23/12/2014 Updated: 09/04/2021
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in nps/servlet/webacc in the Administration Console server in NetIQ Access Manager (NAM) 4.x prior to 4.1 allows remote malicious users to hijack the authentication of administrators for requests that change the administrative password via an fw.SetPassword action.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

microfocus access manager 4.0.1

microfocus access manager 4.0

Exploits

NetIQ Access Manager version 40 SP1 suffers from cross site request forgery, external entity injection, information disclosure, and cross site scripting vulnerabilities ...