Access Manager

Vendor:

First CVE: Mar 23, 2017 · Active for 9 years

24
Total CVEs
More Total CVEs than 95% of tracked products
8.0
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Access Manager over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 23, 2017
9 years ago
Most Recent CVE
Jun 11, 2024
773 days ago

CVE Severity & Scoring

Access Manager24 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local2 (8.3%)
Network22 (91.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low23 (95.8%)
High1 (4.2%)
Unknown0 (0.0%)
User Interaction
None9 (37.5%)
Unknown0 (0.0%)
Required15 (62.5%)
Privileges Required
Low4 (16.7%)
High1 (4.2%)
None19 (79.2%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (24 CVEs).

24 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In NetIQ Access Manager 4.3 and 4.4, a bug exists in Identity Server when accessing a basic SSO connector and downloading the BasicSSO connector plugins on IE11 where an attacker c
Jan 20, 20189.847NONO
iManager Admin Console in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 was vulnerable to iFrame manipulation attacks, which could allow remote users to gain
Mar 23, 20179.830NONO
A Vulnerability exists on Admin Console where an attacker can upload files to the Admin Console server, and potentially execute them. This impacts NetIQ Access Manager versions 4.3
Jan 26, 20189.828NONO
A CSRF exposure exists in NetIQ Access Manager (NAM) 4.4 Identity Server component.
Mar 14, 20188.826NONO
An XSS vulnerability on the /NAGErrors URI in NetIQ Access Manager 4.2 and 4.3 exists because Access Gateway Error pages do not validate the HTTP Referer header.
Apr 24, 20176.122NONO
A cross site request forgery protection mechanism in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 could be circumvented by repeated uploads causing a high l
Mar 23, 20178.822NONO
The certificate upload feature in iManager in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 could be used to upload JSP pages that would be executed as the i
Mar 23, 20178.822NONO
This allows the information exposure to unauthorized users. This issue affects NetIQ Access Manager using version 4.5 or before
Jun 11, 20246.521NONO
Novell Access Manager iManager before 4.3.3 did not validate parameters so that cross site scripting content could be reflected back into the result page using the "a" parameter.
Mar 2, 20186.121NONO
Novell Access Manager Admin Console and IDP servers before 4.3.3 have a URL that could be used by remote attackers to trigger unvalidated redirects to third party sites.
Mar 2, 20186.121NONO

Exploit Exposure

Signals from CVEs in this product scope (24 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (24 CVEs).

Media Mentions

Signals from CVEs in this product scope (24 CVEs).

Top CNAs Publishing CVEs For Access Manager

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
4.516.50.5%00
4.457.24.0%00
4.3.116.10.7%00
4.357.37.5%00
4.2.216.10.7%00
4.2117.20.8%00
4.1107.20.8%00