PT-2021-3857 · Micro Focus · Micro Focus Access Manager

Published

2021-03-26

·

Updated

2025-03-12

·

CVE-2021-22506

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Micro Focus Access Manager versions prior to 5.0
Description The issue is related to an information leakage vulnerability in the Advance configuration of Micro Focus Access Manager. This vulnerability could cause information leakage. The vulnerability is also related to the implementation of the SAML authentication technology, which has insufficient protection of service data, allowing a remote attacker to gain unauthorized access to protected information.
Recommendations For versions prior to 5.0, update to version 5.0 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive information and configuring the Access Manager to minimize the risk of exploitation. Restrict access to the SAML authentication module to minimize the risk of unauthorized access.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-04215
CVE-2021-22506

Affected Products

Micro Focus Access Manager