Vulnerabilities > Netiq > Access Manager > 4.3

DATE CVE VULNERABILITY TITLE RISK
2017-04-24 CVE-2017-5191 Cross-site Scripting vulnerability in Netiq Access Manager 4.2/4.3
An XSS vulnerability on the /NAGErrors URI in NetIQ Access Manager 4.2 and 4.3 exists because Access Gateway Error pages do not validate the HTTP Referer header.
network
low complexity
netiq CWE-79
6.1
2017-04-20 CVE-2017-5183 Cross-site Scripting vulnerability in Netiq Access Manager 4.2.2/4.3/4.3.1
NetIQ Access Manager 4.2.2 and 4.3.x before 4.3.1+, when configured as an Identity Server, has XSS in the AssertionConsumerServiceURL field of a signed AuthnRequest in a samlp:AuthnRequest document.
network
low complexity
netiq CWE-79
6.1
2017-04-20 CVE-2017-5190 Information Exposure vulnerability in Netiq Access Manager 4.1/4.2/4.3
NetIQ Access Manager 4.2 before SP3 HF1 and 4.3 before SP1 HF1, when configured as a SAML 2.0 Identity Server with Virtual Attributes, has a concurrency issue causing information leakage, related to a stale profile.
network
high complexity
netiq CWE-200
3.1