Access Manager
by Microfocus
CVEs (46)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-14803 | Cri | 0.67 | 9.8 | 0.35 | Jan 20, 2018 | In NetIQ Access Manager 4.3 and 4.4, a bug exists in Identity Server when accessing a basic SSO connector and downloading the BasicSSO connector plugins on IE11 where an attacker can execute arbitrary code on the system. | ||
| CVE-2018-1342 | Cri | 0.64 | 9.8 | 0.01 | Jan 26, 2018 | A Vulnerability exists on Admin Console where an attacker can upload files to the Admin Console server, and potentially execute them. This impacts NetIQ Access Manager versions 4.3 and 4.4 as well as the Administrative console. | ||
| CVE-2016-5757 | Cri | 0.64 | 9.8 | 0.02 | Mar 23, 2017 | iManager Admin Console in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 was vulnerable to iFrame manipulation attacks, which could allow remote users to gain access to authentication credentials. | ||
| CVE-2021-22506 | Hig | 0.63 | 7.5 | 0.26 | KEV | Mar 26, 2021 | Advance configuration exposing Information Leakage vulnerability in Micro Focus Access Manager product, affects all versions prior to version 5.0. The vulnerability could cause information leakage. | |
| CVE-2016-5758 | Hig | 0.57 | 8.8 | 0.01 | Mar 23, 2017 | A cross site request forgery protection mechanism in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 could be circumvented by repeated uploads causing a high load. | ||
| CVE-2016-5750 | Hig | 0.57 | 8.8 | 0.01 | Mar 23, 2017 | The certificate upload feature in iManager in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 could be used to upload JSP pages that would be executed as the iManager user, allowing code execution by logged-in remote users. | ||
| CVE-2021-22528 | Hig | 0.52 | 8.0 | 0.01 | Sep 13, 2021 | Reflected Cross Site Scripting (XSS) vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4 | ||
| CVE-2026-11877 | Hig | 0.49 | 7.5 | 0.00 | Jun 24, 2026 | An unauthorized user can modify configuration through API calls that affects the OpenText Access Manager. This issue affects Access Manager before 5.1.3. | ||
| CVE-2021-22496 | Hig | 0.49 | 7.5 | 0.01 | Mar 25, 2021 | Authentication Bypass Vulnerability in Micro Focus Access Manager Product, affects all version prior to version 4.5.3.3. The vulnerability could cause information leakage. | ||
| CVE-2016-5754 | Hig | 0.49 | 7.5 | 0.01 | Mar 23, 2017 | Presence of a .htaccess file could leak information in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before SP2. | ||
| CVE-2016-5752 | Hig | 0.49 | 7.5 | 0.01 | Mar 23, 2017 | The SAML2 implementation in Identity Server in NetIQ Access Manager 4.1 before 4.1.2 HF1 and 4.2 before 4.2.2 was handling unsigned SAML requests incorrectly, leaking results to a potentially malicious "Assertion Consumer Service URL" instead of the original requester. | ||
| CVE-2020-11843 | Med | 0.42 | 6.5 | 0.00 | Jun 11, 2024 | This allows the information exposure to unauthorized users. This issue affects NetIQ Access Manager using version 4.5 or before | ||
| CVE-2016-5755 | Med | 0.42 | 6.5 | 0.01 | Mar 23, 2017 | NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 was vulnerable to clickjacking attacks due to a missing SAMEORIGIN filter in the "high encryption" setting. | ||
| CVE-2026-11878 | Med | 0.40 | 6.1 | 0.00 | Jun 24, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText Access Manager allows Cross-Site Scripting (XSS). This issue affects Access Manager: from 5.1 through 5.1.2. | ||
| CVE-2021-22531 | Med | 0.40 | 6.1 | 0.01 | May 12, 2022 | A bug exist in the input parameter of Access Manager that allows supply of invalid character to trigger cross-site scripting vulnerability. This affects NetIQ Access Manager 4.5 and 5.0 | ||
| CVE-2020-25840 | Med | 0.40 | 6.1 | 0.01 | Mar 26, 2021 | Cross-Site scripting vulnerability in Micro Focus Access Manager product, affects all version prior to version 5.0. The vulnerability could cause configuration destruction. | ||
| CVE-2018-17948 | Med | 0.40 | 6.1 | 0.01 | Nov 20, 2018 | An open redirect vulnerability exists in the Access Manager Identity Provider prior to 4.4 SP3. | ||
| CVE-2018-12480 | Med | 0.40 | 6.1 | 0.01 | Nov 15, 2018 | Mitigates an XSS issue in NetIQ Access Manager versions prior to 4.4 SP3. | ||
| CVE-2017-5191 | Med | 0.40 | 6.1 | 0.01 | Apr 24, 2017 | An XSS vulnerability on the /NAGErrors URI in NetIQ Access Manager 4.2 and 4.3 exists because Access Gateway Error pages do not validate the HTTP Referer header. | ||
| CVE-2017-5183 | Med | 0.40 | 6.1 | 0.01 | Apr 20, 2017 | NetIQ Access Manager 4.2.2 and 4.3.x before 4.3.1+, when configured as an Identity Server, has XSS in the AssertionConsumerServiceURL field of a signed AuthnRequest in a samlp:AuthnRequest document. |
- risk 0.67cvss 9.8epss 0.35
In NetIQ Access Manager 4.3 and 4.4, a bug exists in Identity Server when accessing a basic SSO connector and downloading the BasicSSO connector plugins on IE11 where an attacker can execute arbitrary code on the system.
- risk 0.64cvss 9.8epss 0.01
A Vulnerability exists on Admin Console where an attacker can upload files to the Admin Console server, and potentially execute them. This impacts NetIQ Access Manager versions 4.3 and 4.4 as well as the Administrative console.
- risk 0.64cvss 9.8epss 0.02
iManager Admin Console in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 was vulnerable to iFrame manipulation attacks, which could allow remote users to gain access to authentication credentials.
- risk 0.63cvss 7.5epss 0.26
Advance configuration exposing Information Leakage vulnerability in Micro Focus Access Manager product, affects all versions prior to version 5.0. The vulnerability could cause information leakage.
- risk 0.57cvss 8.8epss 0.01
A cross site request forgery protection mechanism in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 could be circumvented by repeated uploads causing a high load.
- risk 0.57cvss 8.8epss 0.01
The certificate upload feature in iManager in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 could be used to upload JSP pages that would be executed as the iManager user, allowing code execution by logged-in remote users.
- risk 0.52cvss 8.0epss 0.01
Reflected Cross Site Scripting (XSS) vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4
- risk 0.49cvss 7.5epss 0.00
An unauthorized user can modify configuration through API calls that affects the OpenText Access Manager. This issue affects Access Manager before 5.1.3.
- risk 0.49cvss 7.5epss 0.01
Authentication Bypass Vulnerability in Micro Focus Access Manager Product, affects all version prior to version 4.5.3.3. The vulnerability could cause information leakage.
- risk 0.49cvss 7.5epss 0.01
Presence of a .htaccess file could leak information in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before SP2.
- risk 0.49cvss 7.5epss 0.01
The SAML2 implementation in Identity Server in NetIQ Access Manager 4.1 before 4.1.2 HF1 and 4.2 before 4.2.2 was handling unsigned SAML requests incorrectly, leaking results to a potentially malicious "Assertion Consumer Service URL" instead of the original requester.
- risk 0.42cvss 6.5epss 0.00
This allows the information exposure to unauthorized users. This issue affects NetIQ Access Manager using version 4.5 or before
- risk 0.42cvss 6.5epss 0.01
NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 was vulnerable to clickjacking attacks due to a missing SAMEORIGIN filter in the "high encryption" setting.
- risk 0.40cvss 6.1epss 0.00
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText Access Manager allows Cross-Site Scripting (XSS). This issue affects Access Manager: from 5.1 through 5.1.2.
- risk 0.40cvss 6.1epss 0.01
A bug exist in the input parameter of Access Manager that allows supply of invalid character to trigger cross-site scripting vulnerability. This affects NetIQ Access Manager 4.5 and 5.0
- risk 0.40cvss 6.1epss 0.01
Cross-Site scripting vulnerability in Micro Focus Access Manager product, affects all version prior to version 5.0. The vulnerability could cause configuration destruction.
- risk 0.40cvss 6.1epss 0.01
An open redirect vulnerability exists in the Access Manager Identity Provider prior to 4.4 SP3.
- risk 0.40cvss 6.1epss 0.01
Mitigates an XSS issue in NetIQ Access Manager versions prior to 4.4 SP3.
- risk 0.40cvss 6.1epss 0.01
An XSS vulnerability on the /NAGErrors URI in NetIQ Access Manager 4.2 and 4.3 exists because Access Gateway Error pages do not validate the HTTP Referer header.
- risk 0.40cvss 6.1epss 0.01
NetIQ Access Manager 4.2.2 and 4.3.x before 4.3.1+, when configured as an Identity Server, has XSS in the AssertionConsumerServiceURL field of a signed AuthnRequest in a samlp:AuthnRequest document.
Page 1 of 3