5
CVSSv2

CVE-2017-5189

Published: 02/03/2018 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

NetIQ iManager prior to 3.0.3 delivered a SSL private key in a Java application (JAR file) for authentication to Sentinel, allowing malicious users to extract and establish their own connections to the Sentinel appliance.

Vulnerable Product Search on Vulmon Subscribe to Product

netiq imanager 3.0

netiq imanager 3.0.3

netiq imanager 2.7.6

netiq imanager 2.7.5

netiq imanager 2.7.4

netiq imanager 2.7.3

netiq imanager 2.7.2

netiq imanager 2.7.1

netiq imanager 2.7

netiq imanager 2.7.7

netiq imanager 2.7.7.10

netiq imanager 3.0.2