Vulnerabilities > Netiq > Access Manager > High

DATE CVE VULNERABILITY TITLE RISK
2018-03-14 CVE-2018-7677 Cross-Site Request Forgery (CSRF) vulnerability in Netiq Access Manager 4.4
A CSRF exposure exists in NetIQ Access Manager (NAM) 4.4 Identity Server component.
network
low complexity
netiq CWE-352
8.8
2017-03-23 CVE-2016-5758 Cross-Site Request Forgery (CSRF) vulnerability in Netiq Access Manager 4.1/4.2
A cross site request forgery protection mechanism in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 could be circumvented by repeated uploads causing a high load.
network
low complexity
netiq CWE-352
8.8
2017-03-23 CVE-2016-5754 Information Exposure vulnerability in Netiq Access Manager 4.1/4.2
Presence of a .htaccess file could leak information in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before SP2.
network
low complexity
netiq CWE-200
7.5
2017-03-23 CVE-2016-5752 Information Exposure vulnerability in Netiq Access Manager 4.1/4.2
The SAML2 implementation in Identity Server in NetIQ Access Manager 4.1 before 4.1.2 HF1 and 4.2 before 4.2.2 was handling unsigned SAML requests incorrectly, leaking results to a potentially malicious "Assertion Consumer Service URL" instead of the original requester.
network
low complexity
netiq CWE-200
7.5
2017-03-23 CVE-2016-5750 Improper Access Control vulnerability in Netiq Access Manager 4.1/4.2
The certificate upload feature in iManager in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 could be used to upload JSP pages that would be executed as the iManager user, allowing code execution by logged-in remote users.
network
low complexity
netiq CWE-284
8.8