NetIQ Advanced Authentication是英国NetIQ公司的一个应用软件。提供了从用户名和密码转移到一种更安全的方式来保护您的敏感信息。 NetIQ Advanced Authentication 6.3.5.1之前版本存在安全漏洞,该漏洞源于未强制执行账户锁定机制以应对基于API登录的暴力破解攻击,这可能会导致用户账户被攻破或影响服务器性能。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| OpenText | NetIQ Advance Authentication | 6.3.5.1 ~ < | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-38121 | 8.3 HIGH | Weak communication protocol identified in Advance Authentication client application |
| CVE-2021-22509 | 8.1 HIGH | Handling of sensitive data in process memory in NetIQ Advance Authentication |
| CVE-2024-4555 | 7.7 HIGH | User impersonation with MFA when configure in specific way |
| CVE-2024-4554 | 7.3 HIGH | Multiple xss vulnerability in NetIQ Access Manager |
| CVE-2021-22529 | 6.3 MEDIUM | Sensitive Data Exposure leaks potential information in NetIQ Advance Authentication |
| CVE-2021-38122 | 6.2 MEDIUM | Cross-Site Scripting (XSS) in Advance Authentication |
| CVE-2024-4556 | 5.7 MEDIUM | Directory traversal vulnerability in NetIQ Access Manager |
| CVE-2021-38120 | 5.1 MEDIUM | Remote Code Execution using Bash command Injection in backup scheduling functionality in N |
No comments yet