SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2014-5217

Cross-site request forgery (CSRF) vulnerability in nps/servlet/webacc in the Administration Console server in NetIQ Access Manager (NAM) 4.x before 4.1 allows remote attackers to hijack the authentication of administrators for requests that change the…

MEDIUM 6.8EPSS 1.37%

Does this matter?

Lower severity and a low EPSS score (1.37%). Track it; it rarely justifies an emergency change on its own.

Description

Cross-site request forgery (CSRF) vulnerability in nps/servlet/webacc in the Administration Console server in NetIQ Access Manager (NAM) 4.x before 4.1 allows remote attackers to hijack the authentication of administrators for requests that change the administrative password via an fw.SetPassword action.

CVSS 2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
1.37% probability · 70th percentile
CISA KEV
Not listed
Weakness
CWE-352
Affected
microfocus/access manager
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.