NetIQ Access Manager 4.2 before SP3 HF1 and 4.3 before SP1 HF1, when configured as a SAML 2.0 Identity Server with Virtual Attributes, has a concurrency issue causing information leakage, related to a stale profile.
2017-04-20T15:59:00.170
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 3.1 (LOW)
AV:N/AC:M/Au:S/C:P/I:N/A:N
6.8
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | netiq | access_manager | ≤ 4.2 | Yes |
Application | netiq | access_manager | ≤ 4.3 | Yes |