Vulnerabilities > Netiq > Imanager > High

DATE CVE VULNERABILITY TITLE RISK
2018-03-21 CVE-2018-1345 Unspecified vulnerability in Netiq Imanager 2.7.7
NetIQ iManager, versions prior to 3.1, under some circumstances could be susceptible to an elevation of privilege attack.
network
low complexity
netiq
8.8
2018-03-21 CVE-2018-1344 Unspecified vulnerability in Netiq Imanager 2.7.7
Addresses potential communication downgrade attack in NetIQ iManager versions prior to 3.1
network
low complexity
netiq
8.6
2018-03-02 CVE-2017-5189 Improper Authentication vulnerability in Netiq Imanager
NetIQ iManager before 3.0.3 delivered a SSL private key in a Java application (JAR file) for authentication to Sentinel, allowing attackers to extract and establish their own connections to the Sentinel appliance.
network
low complexity
netiq CWE-287
7.5
2017-05-03 CVE-2017-7431 Cross-Site Request Forgery (CSRF) vulnerability in multiple products
Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have persistent CSRF in object management.
network
low complexity
novell netiq CWE-352
8.8
2017-04-27 CVE-2017-5186 Use of a Broken or Risky Cryptographic Algorithm vulnerability in multiple products
Novell iManager 2.7 before SP7 Patch 9, NetIQ iManager 3.x before 3.0.2.1, Novell eDirectory 8.8.x before 8.8 SP8 Patch 9 Hotfix 2, and NetIQ eDirectory 9.x before 9.0.2 Hotfix 2 (9.0.2.2) use the deprecated MD5 hashing algorithm in a communications certificate.
network
low complexity
netiq novell CWE-327
7.5