Summary
Detail | |||
---|---|---|---|
Vendor | Netiq | First view | 2017-11-06 |
Product | Imanager | Last view | 2023-01-26 |
Version | 2.7 | Type | Application |
Update | * | ||
Edition | * | ||
Language | * | ||
Sofware Edition | * | ||
Target Software | * | ||
Target Hardware | * | ||
Other | * | ||
CPE Product | cpe:2.3:a:netiq:imanager |
Activity : Overall
Related : CVE
Date | Alert | Description | |
---|---|---|---|
6.1 | 2023-01-26 | CVE-2022-38758 | Cross-site Scripting (XSS) vulnerability in NetIQ iManager prior to version 3.2.6 allows attacker to execute malicious scripts on the user's browser. This issue affects: Micro Focus NetIQ iManager NetIQ iManager versions prior to 3.2.6 on ALL. |
6.1 | 2018-03-21 | CVE-2018-1347 | The administrative web interface in NetIQ iManager, versions prior to 3.1, are vulnerable to reflected cross site scripting. |
8.8 | 2018-03-21 | CVE-2018-1345 | NetIQ iManager, versions prior to 3.1, under some circumstances could be susceptible to an elevation of privilege attack. |
8.6 | 2018-03-21 | CVE-2018-1344 | Addresses potential communication downgrade attack in NetIQ iManager versions prior to 3.1 |
7.5 | 2018-03-02 | CVE-2017-5189 | NetIQ iManager before 3.0.3 delivered a SSL private key in a Java application (JAR file) for authentication to Sentinel, allowing attackers to extract and establish their own connections to the Sentinel appliance. |
6.1 | 2017-11-06 | CVE-2017-7425 | Multiple potential reflected XSS issues exist in NetIQ iManager versions before 2.7.7 Patch 10 HF2 and 3.0.3.2. |
CWE : Common Weakness Enumeration
% | id | Name |
---|---|---|
75% (3) | CWE-79 | Failure to Preserve Web Page Structure ('Cross-site Scripting') |
25% (1) | CWE-287 | Improper Authentication |