Netiq Imanager vulnerabilities

12 known vulnerabilities affecting netiq/imanager.

Total CVEs
12
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH5MEDIUM6

Vulnerabilities

Page 1 of 1
CVE-2022-38758MEDIUMCVSS 6.1fixed in 3.2.62023-01-26
CVE-2022-38758 [MEDIUM] CWE-79 CVE-2022-38758: Cross-site Scripting (XSS) vulnerability in NetIQ iManager prior to version 3.2.6 allows attacker to Cross-site Scripting (XSS) vulnerability in NetIQ iManager prior to version 3.2.6 allows attacker to execute malicious scripts on the user's browser. This issue affects: Micro Focus NetIQ iManager NetIQ iManager versions prior to 3.2.6 on ALL.
nvd
CVE-2018-12462MEDIUMCVSS 6.1v3.1.1≥ NetIQ iManager, < 3.1.12018-07-10
CVE-2018-12462 [MEDIUM] CWE-79 CVE-2018-12462: NetIQ iManager 3.1.1 addresses potential XSS vulnerabilities. NetIQ iManager 3.1.1 addresses potential XSS vulnerabilities.
cvelistv5nvd
CVE-2018-1345HIGHCVSS 8.8fixed in 3.1≥ prior to version 3.1, < 3.12018-03-21
CVE-2018-1345 [HIGH] CVE-2018-1345: NetIQ iManager, versions prior to 3.1, under some circumstances could be susceptible to an elevation NetIQ iManager, versions prior to 3.1, under some circumstances could be susceptible to an elevation of privilege attack.
cvelistv5nvd
CVE-2018-1344HIGHCVSS 8.6fixed in 3.1≥ iManager versions prior to 3.1, < 3.12018-03-21
CVE-2018-1344 [HIGH] CVE-2018-1344: Addresses potential communication downgrade attack in NetIQ iManager versions prior to 3.1 Addresses potential communication downgrade attack in NetIQ iManager versions prior to 3.1
cvelistv5nvd
CVE-2018-1347MEDIUMCVSS 6.1fixed in 3.1≥ iManager prior to (3.1), < 3.12018-03-21
CVE-2018-1347 [MEDIUM] CWE-79 CVE-2018-1347: The administrative web interface in NetIQ iManager, versions prior to 3.1, are vulnerable to reflect The administrative web interface in NetIQ iManager, versions prior to 3.1, are vulnerable to reflected cross site scripting.
cvelistv5nvd
CVE-2017-5189HIGHCVSS 7.5v2.7v2.7.1+11 more2018-03-02
CVE-2017-5189 [HIGH] CWE-522 CVE-2017-5189: NetIQ iManager before 3.0.3 delivered a SSL private key in a Java application (JAR file) for authent NetIQ iManager before 3.0.3 delivered a SSL private key in a Java application (JAR file) for authentication to Sentinel, allowing attackers to extract and establish their own connections to the Sentinel appliance.
cvelistv5nvd
CVE-2017-7425MEDIUMCVSS 6.1≤ 2.7.7v3.0.3.22017-11-06
CVE-2017-7425 [MEDIUM] CWE-79 CVE-2017-7425: Multiple potential reflected XSS issues exist in NetIQ iManager versions before 2.7.7 Patch 10 HF2 a Multiple potential reflected XSS issues exist in NetIQ iManager versions before 2.7.7 Patch 10 HF2 and 3.0.3.2.
nvd
CVE-2017-7432CRITICALCVSS 9.8v3.0v3.0.1+4 more2017-05-03
CVE-2017-7432 [CRITICAL] CVE-2017-7432: Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have a websh Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have a webshell upload vulnerability.
nvd
CVE-2017-7431HIGHCVSS 8.8v3.0v3.0.1+4 more2017-05-03
CVE-2017-7431 [HIGH] CWE-352 CVE-2017-7431: Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have persist Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have persistent CSRF in object management.
nvd
CVE-2017-7428MEDIUMCVSS 5.3v3.0v3.0.1+4 more2017-05-03
CVE-2017-7428 [MEDIUM] CWE-20 CVE-2017-7428: NetIQ iManager 3.x before 3.0.3.1 has an issue in the renegotiation of connection parameters with To NetIQ iManager 3.x before 3.0.3.1 has an issue in the renegotiation of connection parameters with Tomcat.
nvd
CVE-2017-7430MEDIUMCVSS 6.1v3.0v3.0.1+4 more2017-05-03
CVE-2017-7430 [MEDIUM] CWE-79 CVE-2017-7430: Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have a persi Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have a persistent XSS vulnerability in Framework.
nvd
CVE-2017-5186HIGHCVSS 7.5v3.0v3.0.1+1 more2017-04-27
CVE-2017-5186 [HIGH] CWE-327 CVE-2017-5186: Novell iManager 2.7 before SP7 Patch 9, NetIQ iManager 3.x before 3.0.2.1, Novell eDirectory 8.8.x b Novell iManager 2.7 before SP7 Patch 9, NetIQ iManager 3.x before 3.0.2.1, Novell eDirectory 8.8.x before 8.8 SP8 Patch 9 Hotfix 2, and NetIQ eDirectory 9.x before 9.0.2 Hotfix 2 (9.0.2.2) use the deprecated MD5 hashing algorithm in a communications certificate.
nvd