CVE-2017-5189

NetIQ iManager before 3.0.3 delivered a SSL private key in a Java application (JAR file) for authentication to Sentinel, allowing attackers to extract and establish their own connections to the Sentinel appliance.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:netiq:imanager:2.7:*:*:*:*:*:*:*
cpe:2.3:a:netiq:imanager:2.7.1:*:*:*:*:*:*:*
cpe:2.3:a:netiq:imanager:2.7.2:*:*:*:*:*:*:*
cpe:2.3:a:netiq:imanager:2.7.3:*:*:*:*:*:*:*
cpe:2.3:a:netiq:imanager:2.7.4:*:*:*:*:*:*:*
cpe:2.3:a:netiq:imanager:2.7.5:*:*:*:*:*:*:*
cpe:2.3:a:netiq:imanager:2.7.6:*:*:*:*:*:*:*
cpe:2.3:a:netiq:imanager:2.7.7:p10:*:*:*:*:*:*
cpe:2.3:a:netiq:imanager:2.7.7:p11:*:*:*:*:*:*
cpe:2.3:a:netiq:imanager:2.7.7:p4:*:*:*:*:*:*
cpe:2.3:a:netiq:imanager:2.7.7:p5:*:*:*:*:*:*
cpe:2.3:a:netiq:imanager:2.7.7:p6:*:*:*:*:*:*
cpe:2.3:a:netiq:imanager:2.7.7:p7:*:*:*:*:*:*
cpe:2.3:a:netiq:imanager:2.7.7:p8:*:*:*:*:*:*
cpe:2.3:a:netiq:imanager:2.7.7:p9:*:*:*:*:*:*
cpe:2.3:a:netiq:imanager:2.7.7.10:hf1:*:*:*:*:*:*
cpe:2.3:a:netiq:imanager:2.7.7.10:hf2:*:*:*:*:*:*
cpe:2.3:a:netiq:imanager:3.0:*:*:*:*:*:*:*
cpe:2.3:a:netiq:imanager:3.0:sp1:*:*:*:*:*:*
cpe:2.3:a:netiq:imanager:3.0:sp2:*:*:*:*:*:*
cpe:2.3:a:netiq:imanager:3.0:sp3:*:*:*:*:*:*
cpe:2.3:a:netiq:imanager:3.0:sp4:*:*:*:*:*:*
cpe:2.3:a:netiq:imanager:3.0.2:p1:*:*:*:*:*:*
cpe:2.3:a:netiq:imanager:3.0.3:*:*:*:*:*:*:*

History

07 Nov 2023, 02:49

Type Values Removed Values Added
References (CONFIRM) https://bugzilla.suse.com/show_bug.cgi?id=1021637 - Permissions Required () https://bugzilla.suse.com/show_bug.cgi?id=1021637 -
References (CONFIRM) https://www.netiq.com/support/kb/doc.php?id=7016795 - Vendor Advisory () https://www.netiq.com/support/kb/doc.php?id=7016795 -

Information

Published : 2018-03-02 20:29

Updated : 2023-12-10 12:30


NVD link : CVE-2017-5189

Mitre link : CVE-2017-5189

CVE.ORG link : CVE-2017-5189


JSON object : View

Products Affected

netiq

  • imanager
CWE
CWE-287

Improper Authentication

CWE-522

Insufficiently Protected Credentials