VYPR
Low severity3.1NVD Advisory· Published Apr 20, 2017· Updated May 13, 2026

CVE-2017-5190

CVE-2017-5190

Description

NetIQ Access Manager 4.2 before SP3 HF1 and 4.3 before SP1 HF1, when configured as a SAML 2.0 Identity Server with Virtual Attributes, has a concurrency issue causing information leakage, related to a stale profile.

Affected products

2
  • cpe:2.3:a:netiq:access_manager:*:sp1:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:netiq:access_manager:*:sp1:*:*:*:*:*:*range: <=4.3
    • cpe:2.3:a:netiq:access_manager:*:sp3:*:*:*:*:*:*range: <=4.2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.