PT-2014-6351 · Netiq · Netiq Access Manager

Published

2014-12-23

·

Updated

2021-04-09

·

CVE-2014-5215

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions NetIQ Access Manager (NAM) versions 4.0.0 through 4.0.1 before HF3
Description The issue allows remote authenticated administrators to discover service-account passwords. This can be achieved by sending a request to API endpoints such as "roma/jsp/volsc/monitoring/dev services.jsp" or "roma/jsp/debug/debug.jsp".
Recommendations For versions 4.0.0 through 4.0.1 before HF3, update to version 4.0.1 HF3 to resolve the issue.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-5215

Affected Products

Netiq Access Manager