Vulnerabilities > Netiq > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-11-06 CVE-2017-7425 Cross-site Scripting vulnerability in Netiq Imanager 3.0.3.2
Multiple potential reflected XSS issues exist in NetIQ iManager versions before 2.7.7 Patch 10 HF2 and 3.0.3.2.
network
low complexity
netiq CWE-79
6.1
2017-05-03 CVE-2017-7430 Cross-site Scripting vulnerability in multiple products
Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have a persistent XSS vulnerability in Framework.
network
low complexity
novell netiq CWE-79
6.1
2017-05-03 CVE-2017-7428 Improper Input Validation vulnerability in Netiq Imanager
NetIQ iManager 3.x before 3.0.3.1 has an issue in the renegotiation of connection parameters with Tomcat.
network
low complexity
netiq CWE-20
5.3
2017-04-24 CVE-2017-5191 Cross-site Scripting vulnerability in Netiq Access Manager 4.2/4.3
An XSS vulnerability on the /NAGErrors URI in NetIQ Access Manager 4.2 and 4.3 exists because Access Gateway Error pages do not validate the HTTP Referer header.
network
low complexity
netiq CWE-79
6.1
2017-04-20 CVE-2017-5183 Cross-site Scripting vulnerability in Netiq Access Manager 4.2.2/4.3/4.3.1
NetIQ Access Manager 4.2.2 and 4.3.x before 4.3.1+, when configured as an Identity Server, has XSS in the AssertionConsumerServiceURL field of a signed AuthnRequest in a samlp:AuthnRequest document.
network
low complexity
netiq CWE-79
6.1
2017-03-23 CVE-2016-5756 Cross-site Scripting vulnerability in Netiq Access Manager 4.1/4.2
Multiple components of the web tools in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 were vulnerable to Reflected Cross Site Scripting attacks which could be used to hijack user sessions: nps/servlet/frameservice, nps/servlet/webacc, roma/admin/cntl, roma/jsp/admin/appliance/devicedetail_edit.jsp, roma/jsp/admin/managementip/mgmt_ip_details_frameset.jsp, roma/jsp/admin/managementip/mgmt_ip_details_middleframe.jsp, roma/jsp/volsc/monitoring/appliance.jsp, and roma/jsp/volsc/monitoring/graph.jsp.
network
low complexity
netiq CWE-79
6.1
2017-03-23 CVE-2016-5755 Improper Input Validation vulnerability in Netiq Access Manager 4.1/4.2
NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 was vulnerable to clickjacking attacks due to a missing SAMEORIGIN filter in the "high encryption" setting.
network
low complexity
netiq CWE-20
6.5
2017-03-23 CVE-2016-5751 Cross-site Scripting vulnerability in Netiq Access Manager 4.1/4.2
An unfiltered finalizer target URL in the SAML processing feature in Identity Server in NetIQ Access Manager 4.1 before 4.1.2 HF1 and 4.2 before 4.2.2 could be used to trigger XSS and leak authentication credentials.
network
low complexity
netiq CWE-79
6.1
2017-03-23 CVE-2016-5749 XXE vulnerability in Netiq Access Manager 4.1/4.2
NetIQ Access Manager 4.1 before 4.1.2 HF 1 and 4.2 before 4.2.2 was parsing incoming SAML requests with external entity resolution enabled, which could lead to local file disclosure via an XML External Entity (XXE) attack.
local
low complexity
netiq CWE-611
5.5
2017-03-23 CVE-2016-5748 XXE vulnerability in Netiq Access Manager 4.1/4.2
External Entity Processing (XXE) vulnerability in the "risk score" application of NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 could be used to disclose the content of local files to logged-in users.
local
low complexity
netiq CWE-611
5.5