Netiq
netiq
70 CVEs • 12 products
Products (12)
Click to collapseToggle
Products (12)
Click to collapse
CVEs (70)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Possible Insertion of Sensitive Information into Log File Vulnerability
in Identity Manager has been discovered in
OpenText™
Identity Manager REST Driver. This impact version before 1.1.2.0200. |
This allows the information exposure to unauthorized users. This issue affects NetIQ Access Manager using version 4.5 or before |
Authorization Bypass Through User-Controlled Key vulnerability in NetIQ (OpenText) Client Login Extension on Windows allows Privilege Escalation, Code Injection.This issue only affects NetIQ Client Login Extension: 4...Show more |
Cross-site Scripting (XSS) vulnerability in NetIQ iManager prior to version 3.2.6 allows attacker to execute malicious scripts on the user's browser. This issue affects: Micro Focus NetIQ iManager NetIQ iManager versions...Show more |
File existence disclosure vulnerability in NetIQ Identity Manager plugin prior to version 4.8.5 allows attacker to determine whether a file exists on the filesystem. This issue affects: Micro Focus NetIQ Identity Manager...Show more |
1Netiq 1Self Service Password Reset Jun 17, 2026 Jun 24, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An information leakage exists in Micro Focus NetIQ Self Service Password Reset Software all versions prior to version 4.4. The vulnerability could be exploited to expose sensitive information. |
NetIQ iManager 3.1.1 addresses potential XSS vulnerabilities. |
Fixed issues with NetIQ eDirectory prior to 9.1.1 when checking certificate revocation. |
IDM 4.6 Identity Applications prior to 4.6.2.1 may expose sensitive information. |
NetIQ Identity Reporting, in versions prior to 5.5 Service Pack 1, is susceptible to an XSS attack. |
The NetIQ Identity Manager, in versions prior to 4.7, userapp with log / trace enabled may leak sensitive information. |
The NetIQ Identity Manager user console, in versions prior to 4.7, is susceptible to URL redirection. |
The NetIQ Identity Manager communication channel, in versions prior to 4.7, is susceptible to a DoS attack. |
The NetIQ Identity Manager driver log file, in versions prior to 4.7, provides details that could aid in system enumeration. |
The NetIQ Identity Manager driver log file, in versions prior to 4.7, provides details that could aid in system or configuration enumeration. |
NetIQ Identity Manager driver, in versions prior to 4.7, allows for an SSL handshake renegotiation which could result in a MITM attack. |
The administrative web interface in NetIQ iManager, versions prior to 3.1, are vulnerable to reflected cross site scripting. |
Addresses denial of service attack to eDirectory versions prior to 9.1. |
NetIQ iManager, versions prior to 3.1, under some circumstances could be susceptible to an elevation of privilege attack. |
Addresses potential communication downgrade attack in NetIQ iManager versions prior to 3.1 |