Lucene search

K
cve[email protected]CVE-2017-5190
HistoryApr 20, 2017 - 3:59 p.m.

CVE-2017-5190

2017-04-2015:59:00
CWE-200
web.nvd.nist.gov
17
netiq
access manager
saml 2.0
identity server
information leakage
vulnerability
security
nvd

3.5 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:N/A:N

3.1 Low

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

3.9 Low

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

30.9%

NetIQ Access Manager 4.2 before SP3 HF1 and 4.3 before SP1 HF1, when configured as a SAML 2.0 Identity Server with Virtual Attributes, has a concurrency issue causing information leakage, related to a stale profile.

Affected configurations

NVD
Node
netiqaccess_managerRange4.2sp3
OR
netiqaccess_managerRange4.3sp1

CNA Affected

[
  {
    "product": "NAM Identity Server and SAML2 Service Provider",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "NAM Identity Server and SAML2 Service Provider"
      }
    ]
  }
]

3.5 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:N/A:N

3.1 Low

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

3.9 Low

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

30.9%

Related for CVE-2017-5190