VendorsNetiqaccess_manager4.3
Vulnerabilities

Netiq Access Manager 4.3

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2017-14803
In NetIQ Access Manager 4.3 and 4.4, a bug exists in Identity Server when accessing a basic SSO connector and downloading the BasicSSO connector plugins on IE11 where an attacker can execute arbitrary code on the system.
Published 2018-01-20 · Modified
10.0EPSS 0.346
CVE-2018-1342
A Vulnerability exists on Admin Console where an attacker can upload files to the Admin Console server, and potentially execute them. This impacts NetIQ Access Manager versions 4.3 and 4.4 as well as the Administrative console.
Published 2018-01-26 · Modified
9.8EPSS 0.012
CVE-2017-5191
An XSS vulnerability on the /NAGErrors URI in NetIQ Access Manager 4.2 and 4.3 exists because Access Gateway Error pages do not validate the HTTP Referer header.
Published 2017-04-24 · Modified
6.1EPSS 0.007
CVE-2017-5183
NetIQ Access Manager 4.2.2 and 4.3.x before 4.3.1+, when configured as an Identity Server, has XSS in the AssertionConsumerServiceURL field of a signed AuthnRequest in a samlp:AuthnRequest document.
Published 2017-04-20 · Modified
6.1EPSS 0.007
CVE-2018-7678
XSS vulnerability in NetIQ Access Manager (NAM) Admin Console component
Published 2018-03-14 · Modified
4.8EPSS 0.006