Show filters
70 Total Results
Displaying 61-70 of 70
Sort by:
Attacker Value
Unknown
CVE-2016-5757
Disclosure Date: March 23, 2017 (last updated November 08, 2023)
iManager Admin Console in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 was vulnerable to iFrame manipulation attacks, which could allow remote users to gain access to authentication credentials.
0
Attacker Value
Unknown
CVE-2016-5754
Disclosure Date: March 23, 2017 (last updated November 08, 2023)
Presence of a .htaccess file could leak information in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before SP2.
0
Attacker Value
Unknown
CVE-2015-0787
Disclosure Date: October 27, 2016 (last updated November 08, 2023)
XSS in NetIQ Designer for Identity Manager before 4.5.3 allows remote attackers to inject arbitrary HTML code via the accessMgrDN value of the forgotUser.do CGI.
0
Attacker Value
Unknown
CVE-2016-1592
Disclosure Date: October 27, 2016 (last updated November 08, 2023)
XSS in NetIQ Designer for Identity Manager before 4.5.3 allows remote attackers to inject arbitrary HTML code via the nrfEntitlementReport.do CGI.
0
Attacker Value
Unknown
CVE-2016-1605
Disclosure Date: August 01, 2016 (last updated November 08, 2023)
Directory traversal vulnerability in the ReportViewServlet servlet in the server in NetIQ Sentinel 7.4.x before 7.4.2 allows remote attackers to read arbitrary files via a PREVIEW value for the fileType field.
0
Attacker Value
Unknown
CVE-2014-4509
Disclosure Date: June 21, 2014 (last updated October 05, 2023)
The MKDQUOTESAFE function in the Fan-out driver scripts in Fan-Out Platform Services in Novell Identity Manager (aka IDM) 4.0.2 allows local users to execute arbitrary commands by leveraging eDirectory POSIX attribute changes to insert shell metacharacters.
0
Attacker Value
Unknown
CVE-2007-4526
Disclosure Date: August 25, 2007 (last updated October 04, 2023)
The Client Login Extension (CLE) in Novell Identity Manager before 3.5.1 20070730 stores the username and password in a local file, which allows local users to obtain sensitive information by reading this file.
0
Attacker Value
Unknown
CVE-2006-4803
Disclosure Date: September 14, 2006 (last updated October 04, 2023)
The Fan-Out Linux and UNIX receiver scripts in Novell Identity Manager (IDM) 3.0.1 allows local users to execute arbitrary commands via unspecified vectors involving certain environment variables and "code injection."
0
Attacker Value
Unknown
CVE-2006-4506
Disclosure Date: August 31, 2006 (last updated October 04, 2023)
idmlib.sh in nxdrv in Novell Identity Manager (IDM) 3.0.1 allows local users to execute arbitrary commands via unspecified vectors, possibly involving the " (quote) and \ (backslash) characters and eval injection.
0
Attacker Value
Unknown
CVE-2005-1244
Disclosure Date: April 20, 2005 (last updated February 22, 2025)
Directory traversal vulnerability in the third party tool from NetIQ, as used to secure the iSeries AS/400 FTP server, allows remote attackers to access arbitrary files, including those from qsys.lib, via ".." sequences in a GET request. NOTE: the vendor has disputed this issue, saying that "neither NetIQ Security Manager nor our iSeries Security Solutions are vulnerable.
0