Show filters
614 Total Results
Displaying 381-390 of 614
Sort by:
Attacker Value
Unknown

IDM URL Redirection attack

Disclosure Date: March 28, 2018 (last updated November 08, 2023)
The NetIQ Identity Manager user console, in versions prior to 4.7, is susceptible to URL redirection.
0
Attacker Value
Unknown

NetIQ Identity Manager SSL Renegotiation

Disclosure Date: March 26, 2018 (last updated November 08, 2023)
NetIQ Identity Manager driver, in versions prior to 4.7, allows for an SSL handshake renegotiation which could result in a MITM attack.
0
Attacker Value
Unknown

NetIQ Identity Manager DoS Attack

Disclosure Date: March 26, 2018 (last updated November 08, 2023)
The NetIQ Identity Manager communication channel, in versions prior to 4.7, is susceptible to a DoS attack.
0
Attacker Value
Unknown

NetIQ Identity Manager Driver Component Information Leakage

Disclosure Date: March 26, 2018 (last updated November 08, 2023)
The NetIQ Identity Manager driver log file, in versions prior to 4.7, provides details that could aid in system enumeration.
0
Attacker Value
Unknown

NetIQ Identity Manager Driver Component Log File Information Leakage

Disclosure Date: March 26, 2018 (last updated November 08, 2023)
The NetIQ Identity Manager driver log file, in versions prior to 4.7, provides details that could aid in system or configuration enumeration.
0
Attacker Value
Unknown

CVE-2018-8899

Disclosure Date: March 22, 2018 (last updated November 26, 2024)
IdentityServer IdentityServer4 1.x before 1.5.3 and 2.x before 2.1.3 does not encode the redirect URI on the authorization response page, which might lead to XSS in some configurations.
0
Attacker Value
Unknown

CVE-2018-1443

Disclosure Date: March 08, 2018 (last updated November 26, 2024)
An XML parsing vulnerability affects IBM SAML-based single sign-on (SSO) systems (IBM Security Access Manager 9.0.0 - 9.0.4 and IBM Tivoli Federated Identity Manager 6.2 - 6.0.2.) This vulnerability can allow an attacker with authenticated access to trick SAML systems into authenticating as a different user without knowledge of the victim users password. IBM X-Force ID: 139754.
0
Attacker Value
Unknown

CVE-2018-1182

Disclosure Date: March 08, 2018 (last updated November 26, 2024)
An issue was discovered in EMC RSA Identity Governance and Lifecycle versions 7.0.1, 7.0.2, all patch levels (hardware appliance and software bundle deployments only); RSA Via Lifecycle and Governance version 7.0, all patch levels (hardware appliance and software bundle deployments only); RSA Identity Management & Governance (RSA IMG) versions 6.9.0, 6.9.1, all patch levels (hardware appliance and software bundle deployments only). It allows certain OS level users to execute arbitrary scripts with root level privileges.
0
Attacker Value
Unknown

CVE-2018-0221

Disclosure Date: March 08, 2018 (last updated November 26, 2024)
A vulnerability in specific CLI commands for the Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to perform command injection to the underlying operating system or cause a hang or disconnect of the user session. The attacker needs valid administrator credentials for the device. The vulnerability is due to incomplete input validation of user input for certain CLI ISE configuration commands. An attacker could exploit this vulnerability by authenticating as an administrative user, issuing a specific CLI command, and entering crafted, malicious user input for the command parameters. An exploit could allow the attacker to perform command injection to the lower-level Linux operating system. It is also possible the attacker could cause the ISE user interface for this management session to hang or disconnect. Cisco Bug IDs: CSCvg95479.
0
Attacker Value
Unknown

CVE-2018-0215

Disclosure Date: March 08, 2018 (last updated November 26, 2024)
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF protections on the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to follow a crafted link. A successful exploit could allow the attacker to perform arbitrary actions on a targeted device via a web browser and with the privileges of the user. Cisco Bug IDs: CSCuv32863.
0