Vulnerabilities > Netiq

DATE CVE VULNERABILITY TITLE RISK
2018-03-28 CVE-2018-7674 Open Redirect vulnerability in Netiq Identity Manager 4.5/4.6
The NetIQ Identity Manager user console, in versions prior to 4.7, is susceptible to URL redirection.
network
low complexity
netiq CWE-601
6.1
2018-03-26 CVE-2018-7673 Unspecified vulnerability in Netiq Identity Manager 4.5/4.6
The NetIQ Identity Manager communication channel, in versions prior to 4.7, is susceptible to a DoS attack.
network
low complexity
netiq
7.5
2018-03-26 CVE-2018-1350 Information Exposure Through Log Files vulnerability in Netiq Identity Manager 4.5/4.6
The NetIQ Identity Manager driver log file, in versions prior to 4.7, provides details that could aid in system enumeration.
network
low complexity
netiq CWE-532
5.3
2018-03-26 CVE-2018-1349 Information Exposure Through Log Files vulnerability in Netiq Identity Manager 4.5/4.6
The NetIQ Identity Manager driver log file, in versions prior to 4.7, provides details that could aid in system or configuration enumeration.
network
low complexity
netiq CWE-532
5.3
2018-03-26 CVE-2018-1348 Unspecified vulnerability in Netiq Identity Manager 4.5/4.6
NetIQ Identity Manager driver, in versions prior to 4.7, allows for an SSL handshake renegotiation which could result in a MITM attack.
network
high complexity
netiq
7.4
2018-03-21 CVE-2018-1347 Cross-site Scripting vulnerability in Netiq Imanager 2.7.7
The administrative web interface in NetIQ iManager, versions prior to 3.1, are vulnerable to reflected cross site scripting.
network
low complexity
netiq CWE-79
6.1
2018-03-21 CVE-2018-1346 Unspecified vulnerability in Netiq Edirectory
Addresses denial of service attack to eDirectory versions prior to 9.1.
network
low complexity
netiq
7.5
2018-03-21 CVE-2018-1345 Unspecified vulnerability in Netiq Imanager 2.7.7
NetIQ iManager, versions prior to 3.1, under some circumstances could be susceptible to an elevation of privilege attack.
network
low complexity
netiq
8.8
2018-03-21 CVE-2018-1344 Unspecified vulnerability in Netiq Imanager 2.7.7
Addresses potential communication downgrade attack in NetIQ iManager versions prior to 3.1
network
low complexity
netiq
8.6
2018-03-14 CVE-2018-7678 Cross-site Scripting vulnerability in Netiq Access Manager 4.3/4.4
A cross site scripting vulnerability exist in the Administration Console in NetIQ Access Manager (NAM) 4.3 and 4.4.
network
low complexity
netiq CWE-79
4.8