CVE-2014-5217
Cross-site request forgery (CSRF) vulnerability in nps/servlet/webacc in the Administration Console server in NetIQ Access Manager (NAM) 4.x before 4.1 allows remote attackers to hijack the authentication of administrators for requests that change the…
Does this matter?
Lower severity and a low EPSS score (1.37%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site request forgery (CSRF) vulnerability in nps/servlet/webacc in the Administration Console server in NetIQ Access Manager (NAM) 4.x before 4.1 allows remote attackers to hijack the authentication of administrators for requests that change the administrative password via an fw.SetPassword action.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 1.37% probability · 70th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352
- Affected
- microfocus/access manager
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/129658/NetIQ-Access-Manager-4.0-SP1-XSS-CSRF-XXE-Injection-Disclosure.htmlExploit
- http://seclists.org/fulldisclosure/2014/Dec/78Exploit
- https://www.novell.com/support/kb/doc.php?id=7015997Exploit, Vendor Advisory
- https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20141218-2_Novell_NetIQ_Access_Manager_Multiple_Vulnerabilities_v10.txtExploit
- http://packetstormsecurity.com/files/129658/NetIQ-Access-Manager-4.0-SP1-XSS-CSRF-XXE-Injection-Disclosure.htmlExploit
- http://seclists.org/fulldisclosure/2014/Dec/78Exploit
- https://www.novell.com/support/kb/doc.php?id=7015997Exploit, Vendor Advisory
- https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20141218-2_Novell_NetIQ_Access_Manager_Multiple_Vulnerabilities_v10.txtExploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.