← Back

CVE-2017-5189

nvd nist
Published: Mar 2, 2018Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

NetIQ iManager before 3.0.3 delivered a SSL private key in a Java application (JAR file) for authentication to Sentinel, allowing attackers to extract and establish their own connections to the Sentinel appliance.

Affected (24)

Products: Netiq: Imanager
1 product
Imanager
Configuration A
24 vulnerable
Vulnerable SoftwareAffected Versions
Netiq
Version 2.7.1
Version 2.7.2
Version 2.7.3
Version 2.7.4
Version 2.7.5
Version 2.7.6
Version 2.7.7.10 hf1
Version 2.7.7.10 hf2
Version 2.7.7 p10
Version 2.7.7 p11
Version 2.7.7 p4
Version 2.7.7 p5
Version 2.7.7 p6
Version 2.7.7 p7
Version 2.7.7 p8
Version 2.7.7 p9
Version 2.7
Version 3.0.2 p1
Version 3.0.3
Version 3.0
Version 3.0 sp1
Version 3.0 sp2
Version 3.0 sp3
Version 3.0 sp4

References (4)

Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.