NetIQ iManager before 3.0.3 delivered a SSL private key in a Java application (JAR file) for authentication to Sentinel, allowing attackers to extract and establish their own connections to the Sentinel appliance.
2018-03-02T20:29:00.380
2024-11-21T03:27:13.933
Modified
CVSSv3.0: 4.3 (MEDIUM)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | netiq | imanager | 2.7 | Yes |
Application | netiq | imanager | 2.7.1 | Yes |
Application | netiq | imanager | 2.7.2 | Yes |
Application | netiq | imanager | 2.7.3 | Yes |
Application | netiq | imanager | 2.7.4 | Yes |
Application | netiq | imanager | 2.7.5 | Yes |
Application | netiq | imanager | 2.7.6 | Yes |
Application | netiq | imanager | 2.7.7 | Yes |
Application | netiq | imanager | 2.7.7 | Yes |
Application | netiq | imanager | 2.7.7 | Yes |
Application | netiq | imanager | 2.7.7 | Yes |
Application | netiq | imanager | 2.7.7 | Yes |
Application | netiq | imanager | 2.7.7 | Yes |
Application | netiq | imanager | 2.7.7 | Yes |
Application | netiq | imanager | 2.7.7 | Yes |
Application | netiq | imanager | 2.7.7.10 | Yes |
Application | netiq | imanager | 2.7.7.10 | Yes |
Application | netiq | imanager | 3.0 | Yes |
Application | netiq | imanager | 3.0 | Yes |
Application | netiq | imanager | 3.0 | Yes |
Application | netiq | imanager | 3.0 | Yes |
Application | netiq | imanager | 3.0 | Yes |
Application | netiq | imanager | 3.0.2 | Yes |
Application | netiq | imanager | 3.0.3 | Yes |