Vulnerability index

Browse CVEs

60 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Access Manager MEDIUM 6.1
CVE-2017-14802

Novell Access Manager Admin Console and IDP servers before 4.3.3 have a URL that could be used by remote attackers to trigger unvalidated redirects t…

Fix: after 4.3
Fix from $1,600 2018-03-02
Access Manager MEDIUM 6.1
CVE-2017-7419

A OAuth application in NetIQ Access Manager 4.3 before 4.3.2 and 4.2 before 4.2.4 allowed cross site scripting attacks due to unescaped "description"…

Fix: 4.2.4 / 4.3.2+
Fix from $1,600 2018-03-02
Privileged Account Manager MEDIUM 6.1
CVE-2017-7438

NetIQ Privileged Account Manager before 3.1 Patch Update 3 allowed cross site scripting attacks via javascript DOM modification using the supplied co…

Fix: after 3.1
Fix from $1,600 2018-03-02
Access Manager MEDIUM 6.1
CVE-2017-9276

Novell Access Manager iManager before 4.3.3 did not validate parameters so that cross site scripting content could be reflected back into the result …

Fix: 4.3.3+
Fix from $1,600 2018-03-02
Identity Manager CRITICAL 9.1
CVE-2017-7426

The NetIQ Identity Manager Plugins before 4.6.1 contained various XML External XML Entity (XXE) handling flaws that could be used by attackers to lea…

Fix: 4.6.1+
Fix from $2,300 2018-03-01
Access Manager MEDIUM 6.1
CVE-2017-14799

A cross site scripting attack in handling the ESP login parameter handling in NetIQ Access Manager before 4.3.3 could be used to inject javascript co…

Fix: 4.3.3+
Fix from $1,600 2018-03-01
Access Manager MEDIUM 6.1
CVE-2017-14800

A reflected cross site scripting attack in the NetIQ Access Manager before 4.3.3 using the "typecontainerid" parameter of the policy editor could all…

Fix: 4.3.3+
Fix from $1,600 2018-03-01
Access Manager CRITICAL 9.8
CVE-2018-1342

A Vulnerability exists on Admin Console where an attacker can upload files to the Admin Console server, and potentially execute them. This impacts Ne…

Mitigation only
Fix from $2,300 2018-01-26
Access Manager CRITICAL 9.8
CVE-2017-14803EPSS 35%

In NetIQ Access Manager 4.3 and 4.4, a bug exists in Identity Server when accessing a basic SSO connector and downloading the BasicSSO connector plug…

Mitigation only
Fix from $2,300 2018-01-20
Imanager MEDIUM 6.1
CVE-2017-7425

Multiple potential reflected XSS issues exist in NetIQ iManager versions before 2.7.7 Patch 10 HF2 and 3.0.3.2.

Fix: after 2.7.7
Fix from $1,600 2017-11-06
Imanager MEDIUM 5.3
CVE-2017-7428

NetIQ iManager 3.x before 3.0.3.1 has an issue in the renegotiation of connection parameters with Tomcat.

No fix yet
Fix from $1,600 2017-05-03
Edirectory HIGH 7.5
CVE-2017-5186

Novell iManager 2.7 before SP7 Patch 9, NetIQ iManager 3.x before 3.0.2.1, Novell eDirectory 8.8.x before 8.8 SP8 Patch 9 Hotfix 2, and NetIQ eDirect…

Fix: after 8.8
Fix from $1,950 2017-04-27
Access Manager MEDIUM 6.1
CVE-2017-5191

An XSS vulnerability on the /NAGErrors URI in NetIQ Access Manager 4.2 and 4.3 exists because Access Gateway Error pages do not validate the HTTP Ref…

Mitigation only
Fix from $1,600 2017-04-24
Access Manager MEDIUM 6.1
CVE-2017-5183

NetIQ Access Manager 4.2.2 and 4.3.x before 4.3.1+, when configured as an Identity Server, has XSS in the AssertionConsumerServiceURL field of a sign…

Mitigation only
Fix from $1,600 2017-04-20
Access Manager CRITICAL 9.8
CVE-2016-5757

iManager Admin Console in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 was vulnerable to iFrame manipulation attacks, which c…

Mitigation only
Fix from $2,300 2017-03-23
Access Governance Suite HIGH 8.8
CVE-2016-1597

A logged-in user in NetIQ Access Governance Suite 6.0 through 6.4 could escalate privileges to administrator.

Mitigation only
Fix from $1,950 2017-03-23
Access Manager HIGH 8.8
CVE-2016-5750

The certificate upload feature in iManager in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 could be used to upload JSP pages …

Mitigation only
Fix from $1,950 2017-03-23
Access Manager HIGH 8.8
CVE-2016-5758

A cross site request forgery protection mechanism in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 could be circumvented by re…

Mitigation only
Fix from $1,950 2017-03-23
Access Manager HIGH 7.5
CVE-2016-5752

The SAML2 implementation in Identity Server in NetIQ Access Manager 4.1 before 4.1.2 HF1 and 4.2 before 4.2.2 was handling unsigned SAML requests inc…

Mitigation only
Fix from $1,950 2017-03-23
Access Manager HIGH 7.5
CVE-2016-5754

Presence of a .htaccess file could leak information in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before SP2.

Mitigation only
Fix from $1,950 2017-03-23
Access Manager MEDIUM 6.5
CVE-2016-5755

NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 was vulnerable to clickjacking attacks due to a missing SAMEORIGIN filter in the…

Mitigation only
Fix from $1,600 2017-03-23
Access Manager MEDIUM 6.1
CVE-2016-5751

An unfiltered finalizer target URL in the SAML processing feature in Identity Server in NetIQ Access Manager 4.1 before 4.1.2 HF1 and 4.2 before 4.2.…

Mitigation only
Fix from $1,600 2017-03-23
Access Manager MEDIUM 6.1
CVE-2016-5756

Multiple components of the web tools in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 were vulnerable to Reflected Cross Site …

Mitigation only
Fix from $1,600 2017-03-23
Access Manager MEDIUM 5.5
CVE-2016-5748

External Entity Processing (XXE) vulnerability in the "risk score" application of NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.…

Mitigation only
Fix from $1,600 2017-03-23
Access Manager MEDIUM 5.5
CVE-2016-5749

NetIQ Access Manager 4.1 before 4.1.2 HF 1 and 4.2 before 4.2.2 was parsing incoming SAML requests with external entity resolution enabled, which cou…

Mitigation only
Fix from $1,600 2017-03-23
Identity Manager MEDIUM 6.1
CVE-2016-1592

XSS in NetIQ Designer for Identity Manager before 4.5.3 allows remote attackers to inject arbitrary HTML code via the nrfEntitlementReport.do CGI.

Fix: after 4.5.2
Fix from $1,600 2016-10-27
Identity Manager MEDIUM 6.1
CVE-2015-0787

XSS in NetIQ Designer for Identity Manager before 4.5.3 allows remote attackers to inject arbitrary HTML code via the accessMgrDN value of the forgot…

Fix: after 4.5.2
Fix from $1,600 2016-10-27
Sentinel MEDIUM 6.5
CVE-2016-1605

Directory traversal vulnerability in the ReportViewServlet servlet in the server in NetIQ Sentinel 7.4.x before 7.4.2 allows remote attackers to read…

Mitigation only
Fix from $1,600 2016-08-01
Identity Manager HIGH 7.2
CVE-2006-4803

The Fan-Out Linux and UNIX receiver scripts in Novell Identity Manager (IDM) 3.0.1 allows local users to execute arbitrary commands via unspecified v…

Patch available
Fix from $1,950 2006-09-14
Pssecure HIGH 7.5
CVE-2005-1244

Directory traversal vulnerability in the third party tool from NetIQ, as used to secure the iSeries AS/400 FTP server, allows remote attackers to acc…

No fix yet
Fix from $1,950 2005-04-20