PT-2017-16375 · Netiq · Netiq Access Manager
Publicado
2017-04-20
·
Atualizado
2017-07-11
·
CVE-2017-5190
CVSS v2.0
3.5
Baixa
| Vetor | AV:N/AC:M/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
NetIQ Access Manager versions 4.2 before SP3 HF1 and 4.3 before SP1 HF1
Description
The issue is related to a concurrency problem that causes information leakage when NetIQ Access Manager is configured as a SAML 2.0 Identity Server with Virtual Attributes. This is due to a stale profile.
Recommendations
For versions 4.2 before SP3 HF1, update to SP3 HF1 or later to resolve the issue.
For versions 4.3 before SP1 HF1, update to SP1 HF1 or later to resolve the issue.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Netiq Access Manager