Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-03-23 CVE-2016-5758 Cross-Site Request Forgery (CSRF) vulnerability in Netiq Access Manager 4.1/4.2
A cross site request forgery protection mechanism in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 could be circumvented by repeated uploads causing a high load.
network
low complexity
netiq CWE-352
8.8
2017-03-23 CVE-2016-5754 Information Exposure vulnerability in Netiq Access Manager 4.1/4.2
Presence of a .htaccess file could leak information in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before SP2.
network
low complexity
netiq CWE-200
7.5
2017-03-23 CVE-2016-5752 Information Exposure vulnerability in Netiq Access Manager 4.1/4.2
The SAML2 implementation in Identity Server in NetIQ Access Manager 4.1 before 4.1.2 HF1 and 4.2 before 4.2.2 was handling unsigned SAML requests incorrectly, leaking results to a potentially malicious "Assertion Consumer Service URL" instead of the original requester.
network
low complexity
netiq CWE-200
7.5
2017-03-23 CVE-2016-5750 Improper Access Control vulnerability in Netiq Access Manager 4.1/4.2
The certificate upload feature in iManager in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 could be used to upload JSP pages that would be executed as the iManager user, allowing code execution by logged-in remote users.
network
low complexity
netiq CWE-284
8.8
2017-03-23 CVE-2016-5747 Improper Access Control vulnerability in Novell Edirectory
A security vulnerability in cookie handling in the http stack implementation in NDSD in Novell eDirectory before 9.0.1 allows remote attackers to bypass intended access restrictions by leveraging predictable cookies.
network
low complexity
novell CWE-284
7.5
2017-03-23 CVE-2016-1602 Code Injection vulnerability in Suse products
A code injection in the supportconfig data collection tool in supportutils in SUSE Linux Enterprise Server 12 and 12-SP1 and SUSE Linux Enterprise Desktop 12 and 12-SP1 could be used by local attackers to execute code as the user running supportconfig (usually root).
local
low complexity
suse CWE-94
7.8
2017-03-23 CVE-2016-1597 Permissions, Privileges, and Access Controls vulnerability in Netiq Access Governance Suite
A logged-in user in NetIQ Access Governance Suite 6.0 through 6.4 could escalate privileges to administrator.
network
low complexity
netiq CWE-264
8.8
2017-03-23 CVE-2017-7235 Improper Input Validation vulnerability in Cloudflare-Scrape Project Cloudflare-Scrape
An issue was discovered in cloudflare-scrape 1.6.6 through 1.7.1.
network
low complexity
cloudflare-scrape-project CWE-20
8.8
2017-03-22 CVE-2017-3864 Unspecified vulnerability in Cisco IOS
A vulnerability in the DHCP client implementation of Cisco IOS (12.2, 12.4, and 15.0 through 15.6) and Cisco IOS XE (3.3 through 3.7) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
network
low complexity
cisco
8.6
2017-03-22 CVE-2017-3859 Use of Externally-Controlled Format String vulnerability in Cisco IOS XE
A vulnerability in the DHCP code for the Zero Touch Provisioning feature of Cisco ASR 920 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to cause an affected device to reload.
network
low complexity
cisco CWE-134
7.5