PT-2017-16375 · Netiq · Netiq Access Manager

Publicado

2017-04-20

·

Atualizado

2017-07-11

·

CVE-2017-5190

CVSS v2.0

3.5

Baixa

VetorAV:N/AC:M/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions NetIQ Access Manager versions 4.2 before SP3 HF1 and 4.3 before SP1 HF1
Description The issue is related to a concurrency problem that causes information leakage when NetIQ Access Manager is configured as a SAML 2.0 Identity Server with Virtual Attributes. This is due to a stale profile.
Recommendations For versions 4.2 before SP3 HF1, update to SP3 HF1 or later to resolve the issue. For versions 4.3 before SP1 HF1, update to SP1 HF1 or later to resolve the issue.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-5190

Produtos afetados

Netiq Access Manager