CVE-2022-26329 – File existence disclosue vulnerability in IDM plugin
https://notcve.org/view.php?id=CVE-2022-26329
File existence disclosure vulnerability in NetIQ Identity Manager plugin prior to version 4.8.5 allows attacker to determine whether a file exists on the filesystem. This issue affects: Micro Focus NetIQ Identity Manager NetIQ Identity Manager versions prior to 4.8.5 on ALL. Vulnerabilidad de divulgación de existencia de archivos en el complemento NetIQ Identity Manager anterior a la versión 4.8.5 permite a un atacante determinar si un archivo existe en el sistema de archivos. Este problema afecta a: Micro Focus NetIQ Identity Manager Versiones de NetIQ Identity Manager anteriores a 4.8.5 en TODOS. • https://www.netiq.com/documentation/identity-manager-48/releasenotes_idm485/data/software-fixes.html • CWE-538: Insertion of Sensitive Information into Externally-Accessible File or Directory CWE-668: Exposure of Resource to Wrong Sphere •
CVE-2017-9284 – IDM 4.6 Identity Applications information leakage
https://notcve.org/view.php?id=CVE-2017-9284
IDM 4.6 Identity Applications prior to 4.6.2.1 may expose sensitive information. IDM 4.6 Identity Applications en versiones anteriores a la 4.6.2.1 puede exponer información sensible. • https://download.microfocus.com/Download?buildid=Xg1dZMVbBzs~ • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2018-7674 – IDM URL Redirection attack
https://notcve.org/view.php?id=CVE-2018-7674
The NetIQ Identity Manager user console, in versions prior to 4.7, is susceptible to URL redirection. La consola de usuario de NetIQ Identity Manager, en versiones anteriores a la 4.7, es susceptible a la redirección de URL. • https://www.netiq.com/documentation/identity-manager-47/releasenotes_idm47/data/releasenotes_idm47.html • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •
CVE-2018-7676 – IDM Information Leakage
https://notcve.org/view.php?id=CVE-2018-7676
The NetIQ Identity Manager, in versions prior to 4.7, userapp with log / trace enabled may leak sensitive information. En NetIQ Identity Manager, en versiones anteriores a la 4.7, userapp con log / trace habilitado podría filtrar información sensible. • https://www.netiq.com/documentation/identity-manager-47/releasenotes_idm47/data/releasenotes_idm47.html • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2018-1349 – NetIQ Identity Manager Driver Component Log File Information Leakage
https://notcve.org/view.php?id=CVE-2018-1349
The NetIQ Identity Manager driver log file, in versions prior to 4.7, provides details that could aid in system or configuration enumeration. El archivo de registro del controlador NetIQ Identity Manager, en versiones anteriores a la 4.7, ofrece detalles que podrían ayudar en la enumeración de la configuración o el sistema. • http://www.securityfocus.com/bid/103531 https://www.netiq.com/documentation/identity-manager-47/releasenotes_idm47/data/releasenotes_idm47.html • CWE-532: Insertion of Sensitive Information into Log File •