CVE-2016-5749
5.5
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 1.8 / Impact: 3.6
Source: NVD
Description
NetIQ Access Manager 4.1 before 4.1.2 HF 1 and 4.2 before 4.2.2 was parsing incoming SAML requests with external entity resolution enabled, which could lead to local file disclosure via an XML External Entity (XXE) attack.
Affected (5)
Products: Netiq: Access Manager
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.1 |
References (2)
Source: security@opentext.com
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.