PT-2021-3857 · Micro Focus · Micro Focus Access Manager
Published
2021-03-26
·
Updated
2025-03-12
·
CVE-2021-22506
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Micro Focus Access Manager versions prior to 5.0
Description
The issue is related to an information leakage vulnerability in the Advance configuration of Micro Focus Access Manager. This vulnerability could cause information leakage. The vulnerability is also related to the implementation of the SAML authentication technology, which has insufficient protection of service data, allowing a remote attacker to gain unauthorized access to protected information.
Recommendations
For versions prior to 5.0, update to version 5.0 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive information and configuring the Access Manager to minimize the risk of exploitation. Restrict access to the SAML authentication module to minimize the risk of unauthorized access.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Micro Focus Access Manager