Identity Manager
Vendor:
First CVE: Aug 31, 2006 · Active for 19 years
20
Total CVEs
More Total CVEs than 95% of tracked products
3.3
Avg CVEs / Year
Higher CVE frequency than 84% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 33% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Identity Manager over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 31, 2006
19 years ago
Most Recent CVE
Jan 26, 2023
1,278 days ago
CVE Severity & Scoring
Identity Manager20 CVEs
10%
45%
30%
15%
All CVEs352,785 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network16 (80.0%)
Unknown4 (20.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (70.0%)
High2 (10.0%)
Unknown4 (20.0%)
User Interaction
None12 (60.0%)
Unknown4 (20.0%)
Required4 (20.0%)
Privileges Required
Low0 (0.0%)
High1 (5.0%)
None15 (75.0%)
Unknown4 (20.0%)
Top CVEs
Signals from CVEs in this product scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-9278CRITICAL The NetIQ Identity Manager Oracle EBS driver before 4.0.2.0 sent EBS logs containing the driver authentication password, potentially disclosing this to attackers able to read the E | Mar 2, 2018 | 9.8 | 30 | NO | NO |
CVE-2017-7434CRITICAL In the JDBC driver of NetIQ Identity Manager before 4.6 sending out incorrect XML configurations could result in passwords being logged into exception logfiles. | Mar 2, 2018 | 9.8 | 30 | NO | NO |
CVE-2017-7426CRITICAL The NetIQ Identity Manager Plugins before 4.6.1 contained various XML External XML Entity (XXE) handling flaws that could be used by attackers to leak information or cause denial o | Mar 1, 2018 | 9.1 | 27 | NO | NO |
CVE-2018-7673HIGH The NetIQ Identity Manager communication channel, in versions prior to 4.7, is susceptible to a DoS attack. | Mar 26, 2018 | 7.5 | 24 | NO | NO |
CVE-2017-9280HIGH Some NetIQ Identity Manager Applications before Identity Manager 4.5.6.1 included the session token in GET URLs, potentially allowing exposure of user sessions to untrusted third p | Mar 2, 2018 | 7.5 | 24 | NO | NO |
CVE-2017-9284HIGH IDM 4.6 Identity Applications prior to 4.6.2.1 may expose sensitive information. | Apr 26, 2018 | 7.5 | 23 | NO | NO |
CVE-2017-9279HIGH NetIQ Identity Manager before 4.5.6.1 allowed uploading files with double extensions or non-image content in the Themes handling of the User Application Administration, allowing ma | Mar 2, 2018 | 7.2 | 23 | NO | NO |
CVE-2016-1592MEDIUM XSS in NetIQ Designer for Identity Manager before 4.5.3 allows remote attackers to inject arbitrary HTML code via the nrfEntitlementReport.do CGI. | Oct 27, 2016 | 6.1 | 23 | NO | NO |
CVE-2018-7676MEDIUM The NetIQ Identity Manager, in versions prior to 4.7, userapp with log / trace enabled may leak sensitive information. | Mar 28, 2018 | 5.9 | 21 | NO | NO |
CVE-2018-7674MEDIUM The NetIQ Identity Manager user console, in versions prior to 4.7, is susceptible to URL redirection. | Mar 28, 2018 | 6.1 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (20 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (20 CVEs).
Media Mentions
Signals from CVEs in this product scope (20 CVEs).
Top CNAs Publishing CVEs For Identity Manager
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 4.0.2 | 1 | 4.6 | 0.4% | 0 | 0 |
| 3.0.1 | 2 | 5.4 | 0.5% | 0 | 0 |