Access Manager
Vendor:
First CVE: Mar 23, 2017 · Active for 9 years
24
Total CVEs
More Total CVEs than 95% of tracked products
8.0
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Access Manager over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 23, 2017
9 years ago
Most Recent CVE
Jun 11, 2024
773 days ago
CVE Severity & Scoring
Access Manager24 CVEs
63%
21%
13%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (8.3%)
Network22 (91.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low23 (95.8%)
High1 (4.2%)
Unknown0 (0.0%)
User Interaction
None9 (37.5%)
Unknown0 (0.0%)
Required15 (62.5%)
Privileges Required
Low4 (16.7%)
High1 (4.2%)
None19 (79.2%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (24 CVEs).
24 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-14803CRITICAL In NetIQ Access Manager 4.3 and 4.4, a bug exists in Identity Server when accessing a basic SSO connector and downloading the BasicSSO connector plugins on IE11 where an attacker c | Jan 20, 2018 | 9.8 | 47 | NO | NO |
CVE-2016-5757CRITICAL iManager Admin Console in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 was vulnerable to iFrame manipulation attacks, which could allow remote users to gain | Mar 23, 2017 | 9.8 | 30 | NO | NO |
CVE-2018-1342CRITICAL A Vulnerability exists on Admin Console where an attacker can upload files to the Admin Console server, and potentially execute them. This impacts NetIQ Access Manager versions 4.3 | Jan 26, 2018 | 9.8 | 28 | NO | NO |
CVE-2018-7677HIGH A CSRF exposure exists in NetIQ Access Manager (NAM) 4.4 Identity Server component. | Mar 14, 2018 | 8.8 | 26 | NO | NO |
CVE-2017-5191MEDIUM An XSS vulnerability on the /NAGErrors URI in NetIQ Access Manager 4.2 and 4.3 exists because Access Gateway Error pages do not validate the HTTP Referer header. | Apr 24, 2017 | 6.1 | 22 | NO | NO |
CVE-2016-5758HIGH A cross site request forgery protection mechanism in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 could be circumvented by repeated uploads causing a high l | Mar 23, 2017 | 8.8 | 22 | NO | NO |
CVE-2016-5750HIGH The certificate upload feature in iManager in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 could be used to upload JSP pages that would be executed as the i | Mar 23, 2017 | 8.8 | 22 | NO | NO |
CVE-2020-11843MEDIUM This allows the information exposure to unauthorized users. This issue affects NetIQ Access Manager using version 4.5 or before | Jun 11, 2024 | 6.5 | 21 | NO | NO |
CVE-2017-9276MEDIUM Novell Access Manager iManager before 4.3.3 did not validate parameters so that cross site scripting content could be reflected back into the result page using the "a" parameter. | Mar 2, 2018 | 6.1 | 21 | NO | NO |
CVE-2017-14802MEDIUM Novell Access Manager Admin Console and IDP servers before 4.3.3 have a URL that could be used by remote attackers to trigger unvalidated redirects to third party sites. | Mar 2, 2018 | 6.1 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (24 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (24 CVEs).
Media Mentions
Signals from CVEs in this product scope (24 CVEs).
Top CNAs Publishing CVEs For Access Manager
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 4.5 | 1 | 6.5 | 0.5% | 0 | 0 |
| 4.4 | 5 | 7.2 | 4.0% | 0 | 0 |
| 4.3.1 | 1 | 6.1 | 0.7% | 0 | 0 |
| 4.3 | 5 | 7.3 | 7.5% | 0 | 0 |
| 4.2.2 | 1 | 6.1 | 0.7% | 0 | 0 |
| 4.2 | 11 | 7.2 | 0.8% | 0 | 0 |
| 4.1 | 10 | 7.2 | 0.8% | 0 | 0 |