Vulnerability index

Browse CVEs

60 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2017-14802 Novell Access Manager Admin Console and IDP servers before 4.3.3 have a URL that could be used by remote attackers to trigger unvalidated redirects t… Access Manager after 4.3 Fix from $1,6002018-03-02 MEDIUM 6.1 CVE-2017-7419 A OAuth application in NetIQ Access Manager 4.3 before 4.3.2 and 4.2 before 4.2.4 allowed cross site scripting attacks due to unescaped "description"… Access Manager 4.2.4 / 4.3.2+ Fix from $1,6002018-03-02 MEDIUM 6.1 CVE-2017-7438 NetIQ Privileged Account Manager before 3.1 Patch Update 3 allowed cross site scripting attacks via javascript DOM modification using the supplied co… Privileged Account Manager after 3.1 Fix from $1,6002018-03-02 MEDIUM 6.1 CVE-2017-9276 Novell Access Manager iManager before 4.3.3 did not validate parameters so that cross site scripting content could be reflected back into the result … Access Manager 4.3.3+ Fix from $1,6002018-03-02 CRITICAL 9.1 CVE-2017-7426 The NetIQ Identity Manager Plugins before 4.6.1 contained various XML External XML Entity (XXE) handling flaws that could be used by attackers to lea… Identity Manager 4.6.1+ Fix from $2,3002018-03-01 MEDIUM 6.1 CVE-2017-14799 A cross site scripting attack in handling the ESP login parameter handling in NetIQ Access Manager before 4.3.3 could be used to inject javascript co… Access Manager 4.3.3+ Fix from $1,6002018-03-01 MEDIUM 6.1 CVE-2017-14800 A reflected cross site scripting attack in the NetIQ Access Manager before 4.3.3 using the "typecontainerid" parameter of the policy editor could all… Access Manager 4.3.3+ Fix from $1,6002018-03-01 CRITICAL 9.8 CVE-2018-1342 A Vulnerability exists on Admin Console where an attacker can upload files to the Admin Console server, and potentially execute them. This impacts Ne… Access Manager Mitigation only Fix from $2,3002018-01-26 CRITICAL 9.8 CVE-2017-14803EPSS 35% In NetIQ Access Manager 4.3 and 4.4, a bug exists in Identity Server when accessing a basic SSO connector and downloading the BasicSSO connector plug… Access Manager Mitigation only Fix from $2,3002018-01-20 MEDIUM 6.1 CVE-2017-7425 Multiple potential reflected XSS issues exist in NetIQ iManager versions before 2.7.7 Patch 10 HF2 and 3.0.3.2. Imanager after 2.7.7 Fix from $1,6002017-11-06 MEDIUM 5.3 CVE-2017-7428 NetIQ iManager 3.x before 3.0.3.1 has an issue in the renegotiation of connection parameters with Tomcat. Imanager No fix yet Fix from $1,6002017-05-03 HIGH 7.5 CVE-2017-5186 Novell iManager 2.7 before SP7 Patch 9, NetIQ iManager 3.x before 3.0.2.1, Novell eDirectory 8.8.x before 8.8 SP8 Patch 9 Hotfix 2, and NetIQ eDirect… Edirectory after 8.8 Fix from $1,9502017-04-27 MEDIUM 6.1 CVE-2017-5191 An XSS vulnerability on the /NAGErrors URI in NetIQ Access Manager 4.2 and 4.3 exists because Access Gateway Error pages do not validate the HTTP Ref… Access Manager Mitigation only Fix from $1,6002017-04-24 MEDIUM 6.1 CVE-2017-5183 NetIQ Access Manager 4.2.2 and 4.3.x before 4.3.1+, when configured as an Identity Server, has XSS in the AssertionConsumerServiceURL field of a sign… Access Manager Mitigation only Fix from $1,6002017-04-20 CRITICAL 9.8 CVE-2016-5757 iManager Admin Console in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 was vulnerable to iFrame manipulation attacks, which c… Access Manager Mitigation only Fix from $2,3002017-03-23 HIGH 8.8 CVE-2016-1597 A logged-in user in NetIQ Access Governance Suite 6.0 through 6.4 could escalate privileges to administrator. Access Governance Suite Mitigation only Fix from $1,9502017-03-23 HIGH 8.8 CVE-2016-5750 The certificate upload feature in iManager in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 could be used to upload JSP pages … Access Manager Mitigation only Fix from $1,9502017-03-23 HIGH 8.8 CVE-2016-5758 A cross site request forgery protection mechanism in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 could be circumvented by re… Access Manager Mitigation only Fix from $1,9502017-03-23 HIGH 7.5 CVE-2016-5752 The SAML2 implementation in Identity Server in NetIQ Access Manager 4.1 before 4.1.2 HF1 and 4.2 before 4.2.2 was handling unsigned SAML requests inc… Access Manager Mitigation only Fix from $1,9502017-03-23 HIGH 7.5 CVE-2016-5754 Presence of a .htaccess file could leak information in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before SP2. Access Manager Mitigation only Fix from $1,9502017-03-23 MEDIUM 6.5 CVE-2016-5755 NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 was vulnerable to clickjacking attacks due to a missing SAMEORIGIN filter in the… Access Manager Mitigation only Fix from $1,6002017-03-23 MEDIUM 6.1 CVE-2016-5751 An unfiltered finalizer target URL in the SAML processing feature in Identity Server in NetIQ Access Manager 4.1 before 4.1.2 HF1 and 4.2 before 4.2.… Access Manager Mitigation only Fix from $1,6002017-03-23 MEDIUM 6.1 CVE-2016-5756 Multiple components of the web tools in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 were vulnerable to Reflected Cross Site … Access Manager Mitigation only Fix from $1,6002017-03-23 MEDIUM 5.5 CVE-2016-5748 External Entity Processing (XXE) vulnerability in the "risk score" application of NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.… Access Manager Mitigation only Fix from $1,6002017-03-23 MEDIUM 5.5 CVE-2016-5749 NetIQ Access Manager 4.1 before 4.1.2 HF 1 and 4.2 before 4.2.2 was parsing incoming SAML requests with external entity resolution enabled, which cou… Access Manager Mitigation only Fix from $1,6002017-03-23 MEDIUM 6.1 CVE-2016-1592 XSS in NetIQ Designer for Identity Manager before 4.5.3 allows remote attackers to inject arbitrary HTML code via the nrfEntitlementReport.do CGI. Identity Manager after 4.5.2 Fix from $1,6002016-10-27 MEDIUM 6.1 CVE-2015-0787 XSS in NetIQ Designer for Identity Manager before 4.5.3 allows remote attackers to inject arbitrary HTML code via the accessMgrDN value of the forgot… Identity Manager after 4.5.2 Fix from $1,6002016-10-27 MEDIUM 6.5 CVE-2016-1605 Directory traversal vulnerability in the ReportViewServlet servlet in the server in NetIQ Sentinel 7.4.x before 7.4.2 allows remote attackers to read… Sentinel Mitigation only Fix from $1,6002016-08-01 HIGH 7.2 CVE-2006-4803 The Fan-Out Linux and UNIX receiver scripts in Novell Identity Manager (IDM) 3.0.1 allows local users to execute arbitrary commands via unspecified v… Identity Manager Patch available Fix from $1,9502006-09-14 HIGH 7.5 CVE-2005-1244 Directory traversal vulnerability in the third party tool from NetIQ, as used to secure the iSeries AS/400 FTP server, allows remote attackers to acc… Pssecure No fix yet Fix from $1,9502005-04-20