Vulnerability index

Browse CVEs

60 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Identity Manager Rest Driver HIGH 7.5
CVE-2022-26322

Possible Insertion of Sensitive Information into Log File Vulnerability in Identity Manager has been discovered in OpenText™ Identity Manager REST …

Fix: 1.1.2.0200+
Fix from $1,950 2024-09-12
Access Manager MEDIUM 6.5
CVE-2020-11843

This allows the information exposure to unauthorized users. This issue affects NetIQ Access Manager using version 4.5 or before

Fix: 4.4+
Fix from $1,600 2024-06-11
Client Login Extension HIGH 7.8
CVE-2024-1470

Authorization Bypass Through User-Controlled Key vulnerability in NetIQ (OpenText) Client Login Extension on Windows allows Privilege Escalation, Cod…

Mitigation only
Fix from $1,950 2024-02-29
Imanager MEDIUM 6.1
CVE-2022-38758

Cross-site Scripting (XSS) vulnerability in NetIQ iManager prior to version 3.2.6 allows attacker to execute malicious scripts on the user's browser.…

Fix: 3.2.6+
Fix from $1,600 2023-01-26
Identity Manager MEDIUM 5.3
CVE-2022-26329

File existence disclosure vulnerability in NetIQ Identity Manager plugin prior to version 4.8.5 allows attacker to determine whether a file exists on…

Fix: 4.8.5+
Fix from $1,600 2023-01-26
Self Service Password Reset HIGH 7.5
CVE-2019-11648

An information leakage exists in Micro Focus NetIQ Self Service Password Reset Software all versions prior to version 4.4. The vulnerability could be…

Fix: 4.4+
Fix from $1,950 2019-06-24
Imanager MEDIUM 6.1
CVE-2018-12462

NetIQ iManager 3.1.1 addresses potential XSS vulnerabilities.

No fix yet
Fix from $1,600 2018-07-10
Edirectory HIGH 7.5
CVE-2018-12461

Fixed issues with NetIQ eDirectory prior to 9.1.1 when checking certificate revocation.

Mitigation only
Fix from $1,950 2018-07-10
Identity Manager HIGH 7.5
CVE-2017-9284

IDM 4.6 Identity Applications prior to 4.6.2.1 may expose sensitive information.

Fix: 4.6.2.1+
Fix from $1,950 2018-04-26
Identity Reporting MEDIUM 6.1
CVE-2017-9275

NetIQ Identity Reporting, in versions prior to 5.5 Service Pack 1, is susceptible to an XSS attack.

Fix: 5.5+
Fix from $1,600 2018-04-26
Identity Manager MEDIUM 6.1
CVE-2018-7674

The NetIQ Identity Manager user console, in versions prior to 4.7, is susceptible to URL redirection.

Fix: after 4.6
Fix from $1,600 2018-03-28
Identity Manager MEDIUM 5.9
CVE-2018-7676

The NetIQ Identity Manager, in versions prior to 4.7, userapp with log / trace enabled may leak sensitive information.

Fix: after 4.6
Fix from $1,600 2018-03-28
Identity Manager HIGH 7.5
CVE-2018-7673

The NetIQ Identity Manager communication channel, in versions prior to 4.7, is susceptible to a DoS attack.

Fix: after 4.6
Fix from $1,950 2018-03-26
Identity Manager HIGH 7.4
CVE-2018-1348

NetIQ Identity Manager driver, in versions prior to 4.7, allows for an SSL handshake renegotiation which could result in a MITM attack.

Fix: after 4.6
Fix from $1,950 2018-03-26
Identity Manager MEDIUM 5.3
CVE-2018-1349

The NetIQ Identity Manager driver log file, in versions prior to 4.7, provides details that could aid in system or configuration enumeration.

Fix: after 4.6
Fix from $1,600 2018-03-26
Identity Manager MEDIUM 5.3
CVE-2018-1350

The NetIQ Identity Manager driver log file, in versions prior to 4.7, provides details that could aid in system enumeration.

Fix: after 4.6
Fix from $1,600 2018-03-26
Imanager HIGH 8.8
CVE-2018-1345

NetIQ iManager, versions prior to 3.1, under some circumstances could be susceptible to an elevation of privilege attack.

Fix: 3.1+
Fix from $1,950 2018-03-21
Imanager HIGH 8.6
CVE-2018-1344

Addresses potential communication downgrade attack in NetIQ iManager versions prior to 3.1

Fix: 3.1+
Fix from $1,950 2018-03-21
Edirectory HIGH 7.5
CVE-2018-1346

Addresses denial of service attack to eDirectory versions prior to 9.1.

Fix: 9.1+
Fix from $1,950 2018-03-21
Imanager MEDIUM 6.1
CVE-2018-1347

The administrative web interface in NetIQ iManager, versions prior to 3.1, are vulnerable to reflected cross site scripting.

Fix: 3.1+
Fix from $1,600 2018-03-21
Access Manager HIGH 8.8
CVE-2018-7677

A CSRF exposure exists in NetIQ Access Manager (NAM) 4.4 Identity Server component.

Mitigation only
Fix from $1,950 2018-03-14
Privileged Account Manager CRITICAL 9.8
CVE-2018-1343

PAM exposure enabling unauthenticated access to remote host

Fix: 3.1.0.4 / 3.2.0.3+
Fix from $2,300 2018-03-06
Identity Manager MEDIUM 6.1
CVE-2017-7427

Multiple cross site scripting attacks were found in the Identity Manager Plug-in, hosted on iManager 2.7.7.7, before Identity Manager 4.6.1. In certa…

Fix: 4.6.1+
Fix from $1,600 2018-03-05
Privileged Account Manager MEDIUM 6.1
CVE-2017-7437

NetIQ Privileged Account Manager before 3.1 Patch Update 3 allowed cross site scripting attacks via the "type" and "account" parameters of json reque…

Fix: after 3.0
Fix from $1,600 2018-03-05
Identity Manager CRITICAL 9.8
CVE-2017-7434

In the JDBC driver of NetIQ Identity Manager before 4.6 sending out incorrect XML configurations could result in passwords being logged into exceptio…

Fix: 4.6+
Fix from $2,300 2018-03-02
Identity Manager CRITICAL 9.8
CVE-2017-9278

The NetIQ Identity Manager Oracle EBS driver before 4.0.2.0 sent EBS logs containing the driver authentication password, potentially disclosing this …

Fix: 4.0.2.0+
Fix from $2,300 2018-03-02
Imanager HIGH 7.5
CVE-2017-5189

NetIQ iManager before 3.0.3 delivered a SSL private key in a Java application (JAR file) for authentication to Sentinel, allowing attackers to extrac…

Mitigation only
Fix from $1,950 2018-03-02
Identity Manager HIGH 7.5
CVE-2017-9280

Some NetIQ Identity Manager Applications before Identity Manager 4.5.6.1 included the session token in GET URLs, potentially allowing exposure of use…

Fix: 4.5.6.1+
Fix from $1,950 2018-03-02
Identity Manager HIGH 7.2
CVE-2017-9279

NetIQ Identity Manager before 4.5.6.1 allowed uploading files with double extensions or non-image content in the Themes handling of the User Applicat…

Fix: 4.5.6.1+
Fix from $1,950 2018-03-02
Access Manager MEDIUM 6.1
CVE-2017-14801

Reflected XSS in the NetIQ Access Manager before 4.3.3 allowed attackers to reflect back xss into the called page using the url parameter.

Fix: 4.3.3+
Fix from $1,600 2018-03-02