NetIQ / Access Manager
27 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2024-4554 | Multiple xss vulnerability in NetIQ Access Manager | HIGH | 7.3 | Aug 28, 2024 |
| CVE-2024-4555 | User impersonation with MFA when configure in specific way | HIGH | 7.7 | Aug 28, 2024 |
| CVE-2024-4556 | Directory traversal vulnerability in NetIQ Access Manager | HIGH | 7.5 | Aug 28, 2024 |
| CVE-2020-11843 | Potential information leakage in administrator enabled debug mode | MEDIUM | 6.5 | Jun 11, 2024 |
| CVE-2018-7678 | XSS vulnerability in NetIQ Access Manager (NAM) Admin Console component | MEDIUM | 4.8 | Mar 14, 2018 |
| CVE-2018-7677 | CSRF in NetIQ Access Manager (NAM) Identity Server component | HIGH | 8.8 | Mar 14, 2018 |
| CVE-2017-9276 | XSS Vulnerability in iManager | MEDIUM | 6.1 | Mar 2, 2018 |
| CVE-2017-7419 | NetIQ Access Manager OAuth Consent screen XSS attack | MEDIUM | 6.1 | Mar 2, 2018 |
| CVE-2017-14802 | Unvalidated Redirect in NetIQ Access Manager after upgrading to NAM 4.3 AC and IDP URLs | MEDIUM | 6.1 | Mar 2, 2018 |
| CVE-2017-14801 | Reflected xss in Admin Console REST interface | MEDIUM | 6.1 | Mar 2, 2018 |
| CVE-2017-14800 | Reflected xss on Access Manager iManager UI | MEDIUM | 6.1 | Mar 1, 2018 |
| CVE-2017-14799 | XSS Vulnerability with ESP URL | MEDIUM | 6.1 | Mar 1, 2018 |
| CVE-2018-1342 | A Vulnerability exists on Admin Console where an attacker can upload files to the Admin Console server, and potentially execute them. This impacts NetIQ Access… | CRITICAL | 9.8 | Jan 26, 2018 |
| CVE-2017-14803 | In NetIQ Access Manager 4.3 and 4.4, a bug exists in Identity Server when accessing a basic SSO connector and downloading the BasicSSO connector plugins on IE1… | CRITICAL | 9.8 | Jan 20, 2018 |
| CVE-2017-5191 | An XSS vulnerability on the /NAGErrors URI in NetIQ Access Manager 4.2 and 4.3 exists because Access Gateway Error pages do not validate the HTTP Referer heade… | MEDIUM | 6.1 | Apr 24, 2017 |
| CVE-2017-5183 | NetIQ Access Manager 4.2.2 and 4.3.x before 4.3.1+, when configured as an Identity Server, has XSS in the AssertionConsumerServiceURL field of a signed AuthnRe… | MEDIUM | 6.1 | Apr 20, 2017 |
| CVE-2017-5190 | NetIQ Access Manager 4.2 before SP3 HF1 and 4.3 before SP1 HF1, when configured as a SAML 2.0 Identity Server with Virtual Attributes, has a concurrency issue… | LOW | 3.1 | Apr 20, 2017 |
| CVE-2016-5758 | A cross site request forgery protection mechanism in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 could be circumvented by repeated upl… | HIGH | 8.8 | Mar 23, 2017 |
| CVE-2016-5757 | iManager Admin Console in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 was vulnerable to iFrame manipulation attacks, which could allow… | CRITICAL | 9.8 | Mar 23, 2017 |
| CVE-2016-5756 | Multiple components of the web tools in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 were vulnerable to Reflected Cross Site Scripting… | MEDIUM | 6.1 | Mar 23, 2017 |
| CVE-2016-5755 | NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 was vulnerable to clickjacking attacks due to a missing SAMEORIGIN filter in the "high enc… | MEDIUM | 6.5 | Mar 23, 2017 |
| CVE-2016-5754 | Presence of a .htaccess file could leak information in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before SP2. | HIGH | 7.5 | Mar 23, 2017 |
| CVE-2016-5752 | The SAML2 implementation in Identity Server in NetIQ Access Manager 4.1 before 4.1.2 HF1 and 4.2 before 4.2.2 was handling unsigned SAML requests incorrectly,… | HIGH | 7.5 | Mar 23, 2017 |
| CVE-2016-5751 | An unfiltered finalizer target URL in the SAML processing feature in Identity Server in NetIQ Access Manager 4.1 before 4.1.2 HF1 and 4.2 before 4.2.2 could be… | MEDIUM | 6.1 | Mar 23, 2017 |
| CVE-2016-5750 | The certificate upload feature in iManager in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 could be used to upload JSP pages that would… | HIGH | 8.8 | Mar 23, 2017 |
Showing 1 to 25 of 27 CVEs