Skip to main content

Vendor/product archive

netiq / identity_manager CVEs

Beta · best-effort

20 CVEs tagged to netiq / identity_manager0 Critical, 1 High, 9 Medium, 10 Low, 0 Unrated.

CVE-2022-26329

Published Jan 26, 2023

File existence disclosure vulnerability in NetIQ Identity Manager plugin prior to version 4.8.5 allows attacker to determine whether a file exists on the filesystem. This issue af…

CVSS 1.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2018-7676

Published Mar 28, 2018

The NetIQ Identity Manager, in versions prior to 4.7, userapp with log / trace enabled may leak sensitive information.

CVSS 3.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2018-7674

Published Mar 28, 2018

The NetIQ Identity Manager user console, in versions prior to 4.7, is susceptible to URL redirection.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2018-7673

Published Mar 26, 2018

The NetIQ Identity Manager communication channel, in versions prior to 4.7, is susceptible to a DoS attack.

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1350

Published Mar 26, 2018

The NetIQ Identity Manager driver log file, in versions prior to 4.7, provides details that could aid in system enumeration.

CVSS 2.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2018-1349

Published Mar 26, 2018

The NetIQ Identity Manager driver log file, in versions prior to 4.7, provides details that could aid in system or configuration enumeration.

CVSS 2.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2018-1348

Published Mar 26, 2018

NetIQ Identity Manager driver, in versions prior to 4.7, allows for an SSL handshake renegotiation which could result in a MITM attack.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7427

Published Mar 5, 2018

Multiple cross site scripting attacks were found in the Identity Manager Plug-in, hosted on iManager 2.7.7.7, before Identity Manager 4.6.1. In certain scenarios it was possible t…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-9280

Published Mar 2, 2018

Some NetIQ Identity Manager Applications before Identity Manager 4.5.6.1 included the session token in GET URLs, potentially allowing exposure of user sessions to untrusted third…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-9279

Published Mar 2, 2018

NetIQ Identity Manager before 4.5.6.1 allowed uploading files with double extensions or non-image content in the Themes handling of the User Application Administration, allowing m…

CVSS 2.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2017-9278

Published Mar 2, 2018

The NetIQ Identity Manager Oracle EBS driver before 4.0.2.0 sent EBS logs containing the driver authentication password, potentially disclosing this to attackers able to read the…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2017-7434

Published Mar 2, 2018

In the JDBC driver of NetIQ Identity Manager before 4.6 sending out incorrect XML configurations could result in passwords being logged into exception logfiles.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2017-7426

Published Mar 1, 2018

The NetIQ Identity Manager Plugins before 4.6.1 contained various XML External XML Entity (XXE) handling flaws that could be used by attackers to leak information or cause denial…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-1592

Published Oct 27, 2016

XSS in NetIQ Designer for Identity Manager before 4.5.3 allows remote attackers to inject arbitrary HTML code via the nrfEntitlementReport.do CGI.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0787

Published Oct 27, 2016

XSS in NetIQ Designer for Identity Manager before 4.5.3 allows remote attackers to inject arbitrary HTML code via the accessMgrDN value of the forgotUser.do CGI.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-4509

Published Jun 21, 2014

The MKDQUOTESAFE function in the Fan-out driver scripts in Fan-Out Platform Services in Novell Identity Manager (aka IDM) 4.0.2 allows local users to execute arbitrary commands by…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4803

Published Sep 14, 2006

The Fan-Out Linux and UNIX receiver scripts in Novell Identity Manager (IDM) 3.0.1 allows local users to execute arbitrary commands via unspecified vectors involving certain envir…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4506

Published Aug 31, 2006

idmlib.sh in nxdrv in Novell Identity Manager (IDM) 3.0.1 allows local users to execute arbitrary commands via unspecified vectors, possibly involving the " (quote) and \ (backsla…

CVSS 3.6 · Low
Vendor/product tagsBeta · best-effort
Showing 1-20 of 20 CVEsPage 1 of 1