OpenText NetIQ Access Manager是加拿大OpenText公司的一款全面的移动和网络访问管理工具。 OpenText NetIQ Access Manager 5.0.4.1和5.1之前版本存在安全漏洞,该漏洞源于存在路径遍历漏洞,未能正确限制对受限目录的路径名,可能允许访问敏感信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| OpenText | NetIQ Access Manager | 5.0.4.1 ~ < = | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-38121 | 8.3 HIGH | Weak communication protocol identified in Advance Authentication client application |
| CVE-2021-22530 | 8.2 HIGH | Improper account management vulnerability in NetIQ Advance Authentication |
| CVE-2021-22509 | 8.1 HIGH | Handling of sensitive data in process memory in NetIQ Advance Authentication |
| CVE-2024-4555 | 7.7 HIGH | User impersonation with MFA when configure in specific way |
| CVE-2024-4554 | 7.3 HIGH | Multiple xss vulnerability in NetIQ Access Manager |
| CVE-2021-22529 | 6.3 MEDIUM | Sensitive Data Exposure leaks potential information in NetIQ Advance Authentication |
| CVE-2021-38122 | 6.2 MEDIUM | Cross-Site Scripting (XSS) in Advance Authentication |
| CVE-2021-38120 | 5.1 MEDIUM | Remote Code Execution using Bash command Injection in backup scheduling functionality in N |
No comments yet