VendorsNetiqidentity_managerall versions
Vulnerabilities

Netiq Identity Manager

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

20CVEs
CVE-2017-9278
Avoid password disclosure via EBS event logging in the iManager Oracle driver
Published 2018-03-02 · Modified
9.8EPSS 0.009
CVE-2017-7434
NetIQ Identity Manager JDBC driver could leak passwords in exception traces
Published 2018-03-02 · Modified
9.8EPSS 0.008
CVE-2017-7426
iManager - XML External Entity vulnerabilities
Published 2018-03-01 · Modified
9.1EPSS 0.011
CVE-2017-9279
NetIQ Identity Manager allowed uploading of user icons with incorrect types or extensions
Published 2018-03-02 · Modified
9.0EPSS 0.009
CVE-2017-9284
IDM 4.6 Identity Applications information leakage
Published 2018-04-26 · Modified
7.5EPSS 0.013
CVE-2017-9280
Novell Identity Manager User Application get request url contains the session token.
Published 2018-03-02 · Modified
7.5EPSS 0.011
CVE-2018-7673
NetIQ Identity Manager DoS Attack
Published 2018-03-26 · Modified
7.5EPSS 0.008
CVE-2018-1348
NetIQ Identity Manager SSL Renegotiation
Published 2018-03-26 · Modified
7.4EPSS 0.010
CVE-2006-4803
The Fan-Out Linux and UNIX receiver scripts in Novell Identity Manager (IDM) 3.0.1 allows local users to execute arbitrary commands via unspecified vectors involving certain environment variables and "code injection."
Published 2006-09-14 · Modified
7.2EPSS 0.005
CVE-2017-7427
iManager - Multiple Reflected Cross-Site Scripting attacks
Published 2018-03-05 · Modified
6.1EPSS 0.008
CVE-2015-0787
XSS in NetIQ Designer for Identity Manager before 4.5.3 allows remote attackers to inject arbitrary HTML code via the accessMgrDN value of the forgotUser.do CGI.
Published 2016-10-27 · Modified
6.1EPSS 0.008
CVE-2016-1592
XSS in NetIQ Designer for Identity Manager before 4.5.3 allows remote attackers to inject arbitrary HTML code via the nrfEntitlementReport.do CGI.
Published 2016-10-27 · Modified
6.1EPSS 0.008
CVE-2018-7674
IDM URL Redirection attack
Published 2018-03-28 · Modified
6.1EPSS 0.007
CVE-2018-7676
IDM Information Leakage
Published 2018-03-28 · Modified
5.9EPSS 0.008
CVE-2018-1349
NetIQ Identity Manager Driver Component Log File Information Leakage
Published 2018-03-26 · Modified
5.3EPSS 0.008
CVE-2018-1350
NetIQ Identity Manager Driver Component Information Leakage
Published 2018-03-26 · Modified
5.3EPSS 0.008
CVE-2022-26329
File existence disclosue vulnerability in IDM plugin
Published 2023-01-24 · Modified
5.3EPSS 0.005
CVE-2014-4509
The MKDQUOTESAFE function in the Fan-out driver scripts in Fan-Out Platform Services in Novell Identity Manager (aka IDM) 4.0.2 allows local users to execute arbitrary commands by leveraging eDirectory POSIX attribute changes to insert shell metacharacters.
Published 2014-06-21 · Modified
4.6EPSS 0.004
CVE-2006-4506
idmlib.sh in nxdrv in Novell Identity Manager (IDM) 3.0.1 allows local users to execute arbitrary commands via unspecified vectors, possibly involving the " (quote) and \ (backslash) characters and eval injection.
Published 2006-08-31 · Modified
3.6EPSS 0.005
CVE-2007-4526
The Client Login Extension (CLE) in Novell Identity Manager before 3.5.1 20070730 stores the username and password in a local file, which allows local users to obtain sensitive information by reading this file.
Published 2007-08-25 · Modified
2.1EPSS 0.004