PT-2017-8759 · Netiq · Netiq Access Manager

Publicado

2017-03-23

·

Atualizado

2017-03-24

·

CVE-2016-5749

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions NetIQ Access Manager versions 4.1 through 4.1.2 before HF 1 NetIQ Access Manager versions 4.2 through 4.2.2
Description The issue allows for local file disclosure via an XML External Entity (XXE) attack due to the parsing of incoming SAML requests with external entity resolution enabled.
Recommendations For NetIQ Access Manager versions 4.1 through 4.1.2 before HF 1, update to version 4.1.2 HF 1 or later. For NetIQ Access Manager versions 4.2 through 4.2.2, update to version 4.2.2 or later.

Exploit

Correção

XXE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-5749

Produtos afetados

Netiq Access Manager