Vulnerabilities > Netiq > Imanager > 2.7.7

DATE CVE VULNERABILITY TITLE RISK
2023-01-26 CVE-2022-38758 Cross-site Scripting vulnerability in Netiq Imanager
Cross-site Scripting (XSS) vulnerability in NetIQ iManager prior to version 3.2.6 allows attacker to execute malicious scripts on the user's browser.
network
low complexity
netiq CWE-79
6.1
2018-03-21 CVE-2018-1347 Cross-site Scripting vulnerability in Netiq Imanager 2.7.7
The administrative web interface in NetIQ iManager, versions prior to 3.1, are vulnerable to reflected cross site scripting.
network
low complexity
netiq CWE-79
6.1
2018-03-21 CVE-2018-1345 Unspecified vulnerability in Netiq Imanager 2.7.7
NetIQ iManager, versions prior to 3.1, under some circumstances could be susceptible to an elevation of privilege attack.
network
low complexity
netiq
8.8
2018-03-21 CVE-2018-1344 Unspecified vulnerability in Netiq Imanager 2.7.7
Addresses potential communication downgrade attack in NetIQ iManager versions prior to 3.1
network
low complexity
netiq
8.6
2018-03-02 CVE-2017-5189 Improper Authentication vulnerability in Netiq Imanager
NetIQ iManager before 3.0.3 delivered a SSL private key in a Java application (JAR file) for authentication to Sentinel, allowing attackers to extract and establish their own connections to the Sentinel appliance.
network
low complexity
netiq CWE-287
7.5