Vulnerabilities > Netiq > Access Manager > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2018-03-14 | CVE-2018-7677 | Cross-Site Request Forgery (CSRF) vulnerability in Netiq Access Manager 4.4 A CSRF exposure exists in NetIQ Access Manager (NAM) 4.4 Identity Server component. | 8.8 |
2017-03-23 | CVE-2016-5758 | Cross-Site Request Forgery (CSRF) vulnerability in Netiq Access Manager 4.1/4.2 A cross site request forgery protection mechanism in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 could be circumvented by repeated uploads causing a high load. | 8.8 |
2017-03-23 | CVE-2016-5754 | Information Exposure vulnerability in Netiq Access Manager 4.1/4.2 Presence of a .htaccess file could leak information in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before SP2. | 7.5 |
2017-03-23 | CVE-2016-5752 | Information Exposure vulnerability in Netiq Access Manager 4.1/4.2 The SAML2 implementation in Identity Server in NetIQ Access Manager 4.1 before 4.1.2 HF1 and 4.2 before 4.2.2 was handling unsigned SAML requests incorrectly, leaking results to a potentially malicious "Assertion Consumer Service URL" instead of the original requester. | 7.5 |
2017-03-23 | CVE-2016-5750 | Improper Access Control vulnerability in Netiq Access Manager 4.1/4.2 The certificate upload feature in iManager in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 could be used to upload JSP pages that would be executed as the iManager user, allowing code execution by logged-in remote users. | 8.8 |