NetIQ kayıtları
netiq üreticisine ait 70 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %1,4
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')21
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor8
- CWE-532 Insertion of Sensitive Information into Log File5
- CWE-611 Improper Restriction of XML External Entity Reference3
- CWE-434 Unrestricted Upload of File with Dangerous Type3
- CWE-352 Cross-Site Request Forgery (CSRF)3
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
70 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
49Planlayın | CVE-2017-14803İstismar yok | In NetIQ Access Manager 4.3 and 4.4, a bug exists in Identity Server when accessing a basic SSO connector and downloading the BasicSSO connenetiq · access manager | Kritik9,8 | — | %34,6 | 19 Oca 2018 |
39İzleyin | CVE-2017-7432İstismar yok | Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have a webshell upload vulnerability.novell · imanager | Kritik9,8 | — | %1,5 | 3 May 2017 |
39İzleyin | CVE-2016-5757İstismar yok | iManager Admin Console in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 was vulnerable to iFrame manipulation attacksnetiq · access manager · CWE-200 | Kritik9,8 | — | %1,5 | 23 Mar 2017 |
39İzleyin | CVE-2018-1343İstismar yok | PAM exposure enabling unauthenticated access to remote hostnetiq · privileged account manager · CWE-287 | Kritik9,8 | — | %1,4 | 6 Mar 2018 |
39İzleyin | CVE-2017-9285İstismar yok | Login restrictions not applied when using ebaclient against NetIQ eDirectory EBA interfacenetiq · edirectory · CWE-284 | Kritik9,8 | — | %1,2 | 2 Mar 2018 |
39İzleyin | CVE-2018-1342İstismar yok | A Vulnerability exists on Admin Console where an attacker can upload files to the Admin Console server, and potentially execute them.netiq · access manager · CWE-434 | Kritik9,8 | — | %1,2 | 25 Oca 2018 |
39İzleyin | CVE-2017-9278İstismar yok | Avoid password disclosure via EBS event logging in the iManager Oracle drivernetiq · identity manager · CWE-532 | Kritik9,8 | — | %0,9 | 2 Mar 2018 |
39İzleyin | CVE-2017-7434İstismar yok | NetIQ Identity Manager JDBC driver could leak passwords in exception tracesnetiq · identity manager · CWE-532 | Kritik9,8 | — | %0,8 | 2 Mar 2018 |
36İzleyin | CVE-2017-7426İstismar yok | iManager - XML External Entity vulnerabilitiesnetiq · identity manager · CWE-611 | Kritik9,1 | — | %1,1 | 1 Mar 2018 |
35İzleyin | CVE-2016-1597İstismar yok | A logged-in user in NetIQ Access Governance Suite 6.0 through 6.4 could escalate privileges to administrator.netiq · access governance suite · CWE-264 | Yüksek8,8 | — | %1,2 | 23 Mar 2017 |
35İzleyin | CVE-2016-5750İstismar yok | The certificate upload feature in iManager in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 could be used to upload Jnetiq · access manager · CWE-284 | Yüksek8,8 | — | %1,1 | 23 Mar 2017 |
35İzleyin | CVE-2017-7429İstismar yok | Fix for NetIQ shell code uploadnetiq · edirectory · CWE-434 | Yüksek8,8 | — | %0,8 | 2 Mar 2018 |
35İzleyin | CVE-2018-1345İstismar yok | iManager elevation of privilegenetiq · imanager | Yüksek8,8 | — | %0,6 | 21 Mar 2018 |
35İzleyin | CVE-2017-7431İstismar yok | Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have persistent CSRF in object management.novell · imanager · CWE-352 | Yüksek8,8 | — | %0,6 | 3 May 2017 |
35İzleyin | CVE-2018-7677İstismar yok | CSRF in NetIQ Access Manager (NAM) Identity Server componentnetiq · access manager · CWE-352 | Yüksek8,8 | — | %0,5 | 14 Mar 2018 |
35İzleyin | CVE-2016-5758İstismar yok | A cross site request forgery protection mechanism in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 could be circumvennetiq · access manager · CWE-352 | Yüksek8,8 | — | %0,5 | 23 Mar 2017 |
34İzleyin | CVE-2018-1344İstismar yok | NetIQ iManager Communication Downgrade Attacknetiq · imanager | Yüksek8,6 | — | %0,9 | 21 Mar 2018 |
31İzleyin | CVE-2005-1244İstismar yok | Directory traversal vulnerability in the third party tool from NetIQ, as used to secure the iSeries AS/400 FTP server, allows remote attackenetiq · pssecure | Yüksek7,5 | — | %1,8 | 20 Nis 2005 |
31İzleyin | CVE-2024-1470İstismar yok | Elevation of Privilege attack on NetIQ Client login extensionnetiq · client login extension · CWE-639 | Yüksek7,8 | — | %0,2 | 28 Şub 2024 |
30İzleyin | CVE-2017-9284İstismar yok | IDM 4.6 Identity Applications information leakagenetiq · identity manager · CWE-200 | Yüksek7,5 | — | %1,3 | 26 Nis 2018 |
30İzleyin | CVE-2018-1346İstismar yok | NetIQ eDirectory Denial of Servicenetiq · edirectory | Yüksek7,5 | — | %1,2 | 21 Mar 2018 |
30İzleyin | CVE-2017-5189İstismar yok | private SSL key embedded in JAR file in iManagernetiq · imanager · CWE-522 | Yüksek7,5 | — | %1,2 | 2 Mar 2018 |
30İzleyin | CVE-2017-9280İstismar yok | Novell Identity Manager User Application get request url contains the session token.netiq · identity manager · CWE-598 | Yüksek7,5 | — | %1,1 | 2 Mar 2018 |
30İzleyin | CVE-2019-11648İstismar yok | An information leakage exists in Micro Focus NetIQ Self Service Password Reset Software all versions prior to version 4.4.netiq · self service password reset · CWE-200 | Yüksek7,5 | — | %1,1 | 24 Haz 2019 |
30İzleyin | CVE-2016-5754İstismar yok | Presence of a .htaccess file could leak information in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before SP2.netiq · access manager · CWE-200 | Yüksek7,5 | — | %1,1 | 23 Mar 2017 |
- CVE-2017-1480349Planlayın
In NetIQ Access Manager 4.3 and 4.4, a bug exists in Identity Server when accessing a basic SSO connector and downloading the BasicSSO conne
KritikCVSS 9,8İstismar yokEPSS %35netiq · access manager19 Oca 2018
- CVE-2017-743239İzleyin
Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have a webshell upload vulnerability.
KritikCVSS 9,8İstismar yokEPSS %2novell · imanager3 May 2017
- CVE-2016-575739İzleyin
iManager Admin Console in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 was vulnerable to iFrame manipulation attacks
KritikCVSS 9,8İstismar yokEPSS %2netiq · access manager23 Mar 2017
- CVE-2018-134339İzleyin
PAM exposure enabling unauthenticated access to remote host
KritikCVSS 9,8İstismar yokEPSS %1netiq · privileged account manager6 Mar 2018
- CVE-2017-928539İzleyin
Login restrictions not applied when using ebaclient against NetIQ eDirectory EBA interface
KritikCVSS 9,8İstismar yokEPSS %1netiq · edirectory2 Mar 2018
- CVE-2018-134239İzleyin
A Vulnerability exists on Admin Console where an attacker can upload files to the Admin Console server, and potentially execute them.
KritikCVSS 9,8İstismar yokEPSS %1netiq · access manager25 Oca 2018
- CVE-2017-927839İzleyin
Avoid password disclosure via EBS event logging in the iManager Oracle driver
KritikCVSS 9,8İstismar yokEPSS %1netiq · identity manager2 Mar 2018
- CVE-2017-743439İzleyin
NetIQ Identity Manager JDBC driver could leak passwords in exception traces
KritikCVSS 9,8İstismar yokEPSS %1netiq · identity manager2 Mar 2018
- CVE-2017-742636İzleyin
iManager - XML External Entity vulnerabilities
KritikCVSS 9,1İstismar yokEPSS %1netiq · identity manager1 Mar 2018
- CVE-2016-159735İzleyin
A logged-in user in NetIQ Access Governance Suite 6.0 through 6.4 could escalate privileges to administrator.
YüksekCVSS 8,8İstismar yokEPSS %1netiq · access governance suite23 Mar 2017
- CVE-2016-575035İzleyin
The certificate upload feature in iManager in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 could be used to upload J
YüksekCVSS 8,8İstismar yokEPSS %1netiq · access manager23 Mar 2017
- CVE-2017-742935İzleyin
Fix for NetIQ shell code upload
YüksekCVSS 8,8İstismar yokEPSS %1netiq · edirectory2 Mar 2018
- CVE-2018-134535İzleyin
iManager elevation of privilege
YüksekCVSS 8,8İstismar yokEPSS %1netiq · imanager21 Mar 2018
- CVE-2017-743135İzleyin
Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have persistent CSRF in object management.
YüksekCVSS 8,8İstismar yokEPSS %1novell · imanager3 May 2017
- CVE-2018-767735İzleyin
CSRF in NetIQ Access Manager (NAM) Identity Server component
YüksekCVSS 8,8İstismar yokEPSS %1netiq · access manager14 Mar 2018
- CVE-2016-575835İzleyin
A cross site request forgery protection mechanism in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 could be circumven
YüksekCVSS 8,8İstismar yokEPSS %1netiq · access manager23 Mar 2017
- CVE-2018-134434İzleyin
NetIQ iManager Communication Downgrade Attack
YüksekCVSS 8,6İstismar yokEPSS %1netiq · imanager21 Mar 2018
- CVE-2005-124431İzleyin
Directory traversal vulnerability in the third party tool from NetIQ, as used to secure the iSeries AS/400 FTP server, allows remote attacke
YüksekCVSS 7,5İstismar yokEPSS %2netiq · pssecure20 Nis 2005
- CVE-2024-147031İzleyin
Elevation of Privilege attack on NetIQ Client login extension
YüksekCVSS 7,8İstismar yokEPSS %0netiq · client login extension28 Şub 2024
- CVE-2017-928430İzleyin
IDM 4.6 Identity Applications information leakage
YüksekCVSS 7,5İstismar yokEPSS %1netiq · identity manager26 Nis 2018
- CVE-2018-134630İzleyin
NetIQ eDirectory Denial of Service
YüksekCVSS 7,5İstismar yokEPSS %1netiq · edirectory21 Mar 2018
- CVE-2017-518930İzleyin
private SSL key embedded in JAR file in iManager
YüksekCVSS 7,5İstismar yokEPSS %1netiq · imanager2 Mar 2018
- CVE-2017-928030İzleyin
Novell Identity Manager User Application get request url contains the session token.
YüksekCVSS 7,5İstismar yokEPSS %1netiq · identity manager2 Mar 2018
- CVE-2019-1164830İzleyin
An information leakage exists in Micro Focus NetIQ Self Service Password Reset Software all versions prior to version 4.4.
YüksekCVSS 7,5İstismar yokEPSS %1netiq · self service password reset24 Haz 2019
- CVE-2016-575430İzleyin
Presence of a .htaccess file could leak information in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before SP2.
YüksekCVSS 7,5İstismar yokEPSS %1netiq · access manager23 Mar 2017