Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2022-26322
Possible Insertion of Sensitive Information into Log File Vulnerability
in Identity Manager has been discovered in
OpenText™
Identity Manager REST …
Identity Manager Rest Driver
1.1.2.0200+
MEDIUM 6.5
CVE-2020-11843
This allows the information exposure to unauthorized users. This issue affects NetIQ Access Manager using version 4.5 or before
Access Manager
4.4+
HIGH 7.8
CVE-2024-1470
Authorization Bypass Through User-Controlled Key vulnerability in NetIQ (OpenText) Client Login Extension on Windows allows Privilege Escalation, Cod…
Client Login Extension
Mitigation only
MEDIUM 6.1
CVE-2022-38758
Cross-site Scripting (XSS) vulnerability in NetIQ iManager prior to version 3.2.6 allows attacker to execute malicious scripts on the user's browser.…
Imanager
3.2.6+
MEDIUM 5.3
CVE-2022-26329
File existence disclosure vulnerability in NetIQ Identity Manager plugin prior to version 4.8.5 allows attacker to determine whether a file exists on…
Identity Manager
4.8.5+
HIGH 7.5
CVE-2019-11648
An information leakage exists in Micro Focus NetIQ Self Service Password Reset Software all versions prior to version 4.4. The vulnerability could be…
Self Service Password Reset
4.4+
MEDIUM 6.1
CVE-2018-12462
NetIQ iManager 3.1.1 addresses potential XSS vulnerabilities.
Imanager
No fix yet
HIGH 7.5
CVE-2018-12461
Fixed issues with NetIQ eDirectory prior to 9.1.1 when checking certificate revocation.
Edirectory
Mitigation only
HIGH 7.5
CVE-2017-9284
IDM 4.6 Identity Applications prior to 4.6.2.1 may expose sensitive information.
Identity Manager
4.6.2.1+
MEDIUM 6.1
CVE-2017-9275
NetIQ Identity Reporting, in versions prior to 5.5 Service Pack 1, is susceptible to an XSS attack.
Identity Reporting
5.5+
MEDIUM 6.1
CVE-2018-7674
The NetIQ Identity Manager user console, in versions prior to 4.7, is susceptible to URL redirection.
Identity Manager
after 4.6
MEDIUM 5.9
CVE-2018-7676
The NetIQ Identity Manager, in versions prior to 4.7, userapp with log / trace enabled may leak sensitive information.
Identity Manager
after 4.6
HIGH 7.5
CVE-2018-7673
The NetIQ Identity Manager communication channel, in versions prior to 4.7, is susceptible to a DoS attack.
Identity Manager
after 4.6
HIGH 7.4
CVE-2018-1348
NetIQ Identity Manager driver, in versions prior to 4.7, allows for an SSL handshake renegotiation which could result in a MITM attack.
Identity Manager
after 4.6
MEDIUM 5.3
CVE-2018-1349
The NetIQ Identity Manager driver log file, in versions prior to 4.7, provides details that could aid in system or configuration enumeration.
Identity Manager
after 4.6
MEDIUM 5.3
CVE-2018-1350
The NetIQ Identity Manager driver log file, in versions prior to 4.7, provides details that could aid in system enumeration.
Identity Manager
after 4.6
HIGH 8.8
CVE-2018-1345
NetIQ iManager, versions prior to 3.1, under some circumstances could be susceptible to an elevation of privilege attack.
Imanager
3.1+
HIGH 8.6
CVE-2018-1344
Addresses potential communication downgrade attack in NetIQ iManager versions prior to 3.1
Imanager
3.1+
HIGH 7.5
CVE-2018-1346
Addresses denial of service attack to eDirectory versions prior to 9.1.
Edirectory
9.1+
MEDIUM 6.1
CVE-2018-1347
The administrative web interface in NetIQ iManager, versions prior to 3.1, are vulnerable to reflected cross site scripting.
Imanager
3.1+
HIGH 8.8
CVE-2018-7677
A CSRF exposure exists in NetIQ Access Manager (NAM) 4.4 Identity Server component.
Access Manager
Mitigation only
CRITICAL 9.8
CVE-2018-1343
PAM exposure enabling unauthenticated access to remote host
Privileged Account Manager
3.1.0.4 / 3.2.0.3+
MEDIUM 6.1
CVE-2017-7427
Multiple cross site scripting attacks were found in the Identity Manager Plug-in, hosted on iManager 2.7.7.7, before Identity Manager 4.6.1. In certa…
Identity Manager
4.6.1+
MEDIUM 6.1
CVE-2017-7437
NetIQ Privileged Account Manager before 3.1 Patch Update 3 allowed cross site scripting attacks via the "type" and "account" parameters of json reque…
Privileged Account Manager
after 3.0
CRITICAL 9.8
CVE-2017-7434
In the JDBC driver of NetIQ Identity Manager before 4.6 sending out incorrect XML configurations could result in passwords being logged into exceptio…
Identity Manager
4.6+
CRITICAL 9.8
CVE-2017-9278
The NetIQ Identity Manager Oracle EBS driver before 4.0.2.0 sent EBS logs containing the driver authentication password, potentially disclosing this …
Identity Manager
4.0.2.0+
HIGH 7.5
CVE-2017-5189
NetIQ iManager before 3.0.3 delivered a SSL private key in a Java application (JAR file) for authentication to Sentinel, allowing attackers to extrac…
Imanager
Mitigation only
HIGH 7.5
CVE-2017-9280
Some NetIQ Identity Manager Applications before Identity Manager 4.5.6.1 included the session token in GET URLs, potentially allowing exposure of use…
Identity Manager
4.5.6.1+
HIGH 7.2
CVE-2017-9279
NetIQ Identity Manager before 4.5.6.1 allowed uploading files with double extensions or non-image content in the Themes handling of the User Applicat…
Identity Manager
4.5.6.1+
MEDIUM 6.1
CVE-2017-14801
Reflected XSS in the NetIQ Access Manager before 4.3.3 allowed attackers to reflect back xss into the called page using the url parameter.
Access Manager
4.3.3+