Skip to main content

Vendor archive

netiq CVEs

Beta · best-effort

70 CVEs tagged to vendor netiq5 Critical, 14 High, 34 Medium, 17 Low, 0 Unrated.

CVE-2022-26322

Published Sep 12, 2024

Possible Insertion of Sensitive Information into Log File Vulnerability in Identity Manager has been discovered in OpenText™ Identity Manager REST Driver. This impact version be…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-11843

Published Jun 11, 2024

This allows the information exposure to unauthorized users. This issue affects NetIQ Access Manager using version 4.5 or before

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1470

Published Feb 29, 2024

Authorization Bypass Through User-Controlled Key vulnerability in NetIQ (OpenText) Client Login Extension on Windows allows Privilege Escalation, Code Injection.This issue only…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-38758

Published Jan 26, 2023

Cross-site Scripting (XSS) vulnerability in NetIQ iManager prior to version 3.2.6 allows attacker to execute malicious scripts on the user's browser. This issue affects: Micro Foc…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-26329

Published Jan 26, 2023

File existence disclosure vulnerability in NetIQ Identity Manager plugin prior to version 4.8.5 allows attacker to determine whether a file exists on the filesystem. This issue af…

CVSS 1.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2019-11648

Published Jun 24, 2019

An information leakage exists in Micro Focus NetIQ Self Service Password Reset Software all versions prior to version 4.4. The vulnerability could be exploited to expose sensitive…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-12461

Published Jul 10, 2018

Fixed issues with NetIQ eDirectory prior to 9.1.1 when checking certificate revocation.

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2018-7676

Published Mar 28, 2018

The NetIQ Identity Manager, in versions prior to 4.7, userapp with log / trace enabled may leak sensitive information.

CVSS 3.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2018-7674

Published Mar 28, 2018

The NetIQ Identity Manager user console, in versions prior to 4.7, is susceptible to URL redirection.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2018-7673

Published Mar 26, 2018

The NetIQ Identity Manager communication channel, in versions prior to 4.7, is susceptible to a DoS attack.

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1350

Published Mar 26, 2018

The NetIQ Identity Manager driver log file, in versions prior to 4.7, provides details that could aid in system enumeration.

CVSS 2.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2018-1349

Published Mar 26, 2018

The NetIQ Identity Manager driver log file, in versions prior to 4.7, provides details that could aid in system or configuration enumeration.

CVSS 2.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2018-1348

Published Mar 26, 2018

NetIQ Identity Manager driver, in versions prior to 4.7, allows for an SSL handshake renegotiation which could result in a MITM attack.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1347

Published Mar 21, 2018

The administrative web interface in NetIQ iManager, versions prior to 3.1, are vulnerable to reflected cross site scripting.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1346

Published Mar 21, 2018

Addresses denial of service attack to eDirectory versions prior to 9.1.

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2018-1345

Published Mar 21, 2018

NetIQ iManager, versions prior to 3.1, under some circumstances could be susceptible to an elevation of privilege attack.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1344

Published Mar 21, 2018

Addresses potential communication downgrade attack in NetIQ iManager versions prior to 3.1

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2018-7678

Published Mar 14, 2018

A cross site scripting vulnerability exist in the Administration Console in NetIQ Access Manager (NAM) 4.3 and 4.4.

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2017-7437

Published Mar 5, 2018

NetIQ Privileged Account Manager before 3.1 Patch Update 3 allowed cross site scripting attacks via the "type" and "account" parameters of json requests.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7427

Published Mar 5, 2018

Multiple cross site scripting attacks were found in the Identity Manager Plug-in, hosted on iManager 2.7.7.7, before Identity Manager 4.6.1. In certain scenarios it was possible t…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 70 CVEsPage 1 of 3