Show filters
70 Total Results
Displaying 61-70 of 70
Sort by:
Attacker Value
Unknown

CVE-2016-5757

Disclosure Date: March 23, 2017 (last updated November 08, 2023)
iManager Admin Console in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 was vulnerable to iFrame manipulation attacks, which could allow remote users to gain access to authentication credentials.
0
Attacker Value
Unknown

CVE-2016-5754

Disclosure Date: March 23, 2017 (last updated November 08, 2023)
Presence of a .htaccess file could leak information in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before SP2.
0
Attacker Value
Unknown

CVE-2015-0787

Disclosure Date: October 27, 2016 (last updated November 08, 2023)
XSS in NetIQ Designer for Identity Manager before 4.5.3 allows remote attackers to inject arbitrary HTML code via the accessMgrDN value of the forgotUser.do CGI.
0
Attacker Value
Unknown

CVE-2016-1592

Disclosure Date: October 27, 2016 (last updated November 08, 2023)
XSS in NetIQ Designer for Identity Manager before 4.5.3 allows remote attackers to inject arbitrary HTML code via the nrfEntitlementReport.do CGI.
0
Attacker Value
Unknown

CVE-2016-1605

Disclosure Date: August 01, 2016 (last updated November 08, 2023)
Directory traversal vulnerability in the ReportViewServlet servlet in the server in NetIQ Sentinel 7.4.x before 7.4.2 allows remote attackers to read arbitrary files via a PREVIEW value for the fileType field.
0
Attacker Value
Unknown

CVE-2014-4509

Disclosure Date: June 21, 2014 (last updated October 05, 2023)
The MKDQUOTESAFE function in the Fan-out driver scripts in Fan-Out Platform Services in Novell Identity Manager (aka IDM) 4.0.2 allows local users to execute arbitrary commands by leveraging eDirectory POSIX attribute changes to insert shell metacharacters.
0
Attacker Value
Unknown

CVE-2007-4526

Disclosure Date: August 25, 2007 (last updated October 04, 2023)
The Client Login Extension (CLE) in Novell Identity Manager before 3.5.1 20070730 stores the username and password in a local file, which allows local users to obtain sensitive information by reading this file.
0
Attacker Value
Unknown

CVE-2006-4803

Disclosure Date: September 14, 2006 (last updated October 04, 2023)
The Fan-Out Linux and UNIX receiver scripts in Novell Identity Manager (IDM) 3.0.1 allows local users to execute arbitrary commands via unspecified vectors involving certain environment variables and "code injection."
0
Attacker Value
Unknown

CVE-2006-4506

Disclosure Date: August 31, 2006 (last updated October 04, 2023)
idmlib.sh in nxdrv in Novell Identity Manager (IDM) 3.0.1 allows local users to execute arbitrary commands via unspecified vectors, possibly involving the " (quote) and \ (backslash) characters and eval injection.
0
Attacker Value
Unknown

CVE-2005-1244

Disclosure Date: April 20, 2005 (last updated February 22, 2025)
Directory traversal vulnerability in the third party tool from NetIQ, as used to secure the iSeries AS/400 FTP server, allows remote attackers to access arbitrary files, including those from qsys.lib, via ".." sequences in a GET request. NOTE: the vendor has disputed this issue, saying that "neither NetIQ Security Manager nor our iSeries Security Solutions are vulnerable.
0