
CVE-2017-9275 – NetIQ Identity Reporting XSS exposure
https://notcve.org/view.php?id=CVE-2017-9275
26 Apr 2018 — NetIQ Identity Reporting, in versions prior to 5.5 Service Pack 1, is susceptible to an XSS attack. NetIQ Identity Reporting en versiones anteriores a la 5.5 Service Pack 1 es susceptible a un ataque Cross-Site Scripting (XSS). • https://download.microfocus.com/Download?buildid=iGYyq6xwjhE~&donotredirect=true • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2017-9284 – IDM 4.6 Identity Applications information leakage
https://notcve.org/view.php?id=CVE-2017-9284
26 Apr 2018 — IDM 4.6 Identity Applications prior to 4.6.2.1 may expose sensitive information. IDM 4.6 Identity Applications en versiones anteriores a la 4.6.2.1 puede exponer información sensible. • https://download.microfocus.com/Download?buildid=Xg1dZMVbBzs~ • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2018-7674 – IDM URL Redirection attack
https://notcve.org/view.php?id=CVE-2018-7674
28 Mar 2018 — The NetIQ Identity Manager user console, in versions prior to 4.7, is susceptible to URL redirection. La consola de usuario de NetIQ Identity Manager, en versiones anteriores a la 4.7, es susceptible a la redirección de URL. • https://www.netiq.com/documentation/identity-manager-47/releasenotes_idm47/data/releasenotes_idm47.html • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •

CVE-2018-7676 – IDM Information Leakage
https://notcve.org/view.php?id=CVE-2018-7676
28 Mar 2018 — The NetIQ Identity Manager, in versions prior to 4.7, userapp with log / trace enabled may leak sensitive information. En NetIQ Identity Manager, en versiones anteriores a la 4.7, userapp con log / trace habilitado podría filtrar información sensible. • https://www.netiq.com/documentation/identity-manager-47/releasenotes_idm47/data/releasenotes_idm47.html • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2018-7673 – NetIQ Identity Manager DoS Attack
https://notcve.org/view.php?id=CVE-2018-7673
26 Mar 2018 — The NetIQ Identity Manager communication channel, in versions prior to 4.7, is susceptible to a DoS attack. El canal de comunicación NetIQ Identity Manager, en versiones anteriores a la 4.7, es vulnerable a un ataque de denegación de servicio (DoS). • http://www.securityfocus.com/bid/103533 •

CVE-2018-1348 – NetIQ Identity Manager SSL Renegotiation
https://notcve.org/view.php?id=CVE-2018-1348
26 Mar 2018 — NetIQ Identity Manager driver, in versions prior to 4.7, allows for an SSL handshake renegotiation which could result in a MITM attack. El controlador NetIQ Identity Manager, en versiones anteriores a la 4.7, permite que se produzca una renegociación del protocolo de enlace SSL, lo que podría dar como resultado una ataque Man in the Middle (MitM). • http://www.securityfocus.com/bid/103530 •

CVE-2018-1349 – NetIQ Identity Manager Driver Component Log File Information Leakage
https://notcve.org/view.php?id=CVE-2018-1349
26 Mar 2018 — The NetIQ Identity Manager driver log file, in versions prior to 4.7, provides details that could aid in system or configuration enumeration. El archivo de registro del controlador NetIQ Identity Manager, en versiones anteriores a la 4.7, ofrece detalles que podrían ayudar en la enumeración de la configuración o el sistema. • http://www.securityfocus.com/bid/103531 • CWE-532: Insertion of Sensitive Information into Log File •

CVE-2018-1350 – NetIQ Identity Manager Driver Component Information Leakage
https://notcve.org/view.php?id=CVE-2018-1350
26 Mar 2018 — The NetIQ Identity Manager driver log file, in versions prior to 4.7, provides details that could aid in system enumeration. El archivo de registro del controlador NetIQ Identity Manager, en versiones anteriores a la 4.7, ofrece detalles que podrían ayudar en la enumeración del sistema. • http://www.securityfocus.com/bid/103532 • CWE-532: Insertion of Sensitive Information into Log File •

CVE-2018-1344 – NetIQ iManager Communication Downgrade Attack
https://notcve.org/view.php?id=CVE-2018-1344
21 Mar 2018 — Addresses potential communication downgrade attack in NetIQ iManager versions prior to 3.1 Se trata de un potencial ataque de degradación de comunicaciones en NetIQ iManager, en versiones anteriores a la 3.1. • https://www.netiq.com/documentation/imanager-31/imanager31_releasenotes/data/imanager31_releasenotes.html •

CVE-2018-1345 – iManager elevation of privilege
https://notcve.org/view.php?id=CVE-2018-1345
21 Mar 2018 — NetIQ iManager, versions prior to 3.1, under some circumstances could be susceptible to an elevation of privilege attack. NetIQ iManager, en versiones anteriores a la 3.1, podría ser susceptible bajo ciertas circunstancias a un ataque de elevación de privilegios. • https://www.netiq.com/documentation/imanager-31/imanager31_releasenotes/data/imanager31_releasenotes.html •