Identity Manager

Vendor:

First CVE: Aug 31, 2006 · Active for 19 years

20
Total CVEs
More Total CVEs than 95% of tracked products
3.3
Avg CVEs / Year
Higher CVE frequency than 84% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 33% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Identity Manager over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 31, 2006
19 years ago
Most Recent CVE
Jan 26, 2023
1,278 days ago

CVE Severity & Scoring

Identity Manager20 CVEs
All CVEs352,785 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network16 (80.0%)
Unknown4 (20.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (70.0%)
High2 (10.0%)
Unknown4 (20.0%)
User Interaction
None12 (60.0%)
Unknown4 (20.0%)
Required4 (20.0%)
Privileges Required
Low0 (0.0%)
High1 (5.0%)
None15 (75.0%)
Unknown4 (20.0%)

Top CVEs

Signals from CVEs in this product scope (20 CVEs).

20 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The NetIQ Identity Manager Oracle EBS driver before 4.0.2.0 sent EBS logs containing the driver authentication password, potentially disclosing this to attackers able to read the E
Mar 2, 20189.830NONO
In the JDBC driver of NetIQ Identity Manager before 4.6 sending out incorrect XML configurations could result in passwords being logged into exception logfiles.
Mar 2, 20189.830NONO
The NetIQ Identity Manager Plugins before 4.6.1 contained various XML External XML Entity (XXE) handling flaws that could be used by attackers to leak information or cause denial o
Mar 1, 20189.127NONO
The NetIQ Identity Manager communication channel, in versions prior to 4.7, is susceptible to a DoS attack.
Mar 26, 20187.524NONO
Some NetIQ Identity Manager Applications before Identity Manager 4.5.6.1 included the session token in GET URLs, potentially allowing exposure of user sessions to untrusted third p
Mar 2, 20187.524NONO
IDM 4.6 Identity Applications prior to 4.6.2.1 may expose sensitive information.
Apr 26, 20187.523NONO
NetIQ Identity Manager before 4.5.6.1 allowed uploading files with double extensions or non-image content in the Themes handling of the User Application Administration, allowing ma
Mar 2, 20187.223NONO
XSS in NetIQ Designer for Identity Manager before 4.5.3 allows remote attackers to inject arbitrary HTML code via the nrfEntitlementReport.do CGI.
Oct 27, 20166.123NONO
The NetIQ Identity Manager, in versions prior to 4.7, userapp with log / trace enabled may leak sensitive information.
Mar 28, 20185.921NONO
The NetIQ Identity Manager user console, in versions prior to 4.7, is susceptible to URL redirection.
Mar 28, 20186.120NONO

Exploit Exposure

Signals from CVEs in this product scope (20 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (20 CVEs).

Media Mentions

Signals from CVEs in this product scope (20 CVEs).

Top CNAs Publishing CVEs For Identity Manager

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
4.0.214.60.4%00
3.0.125.40.5%00