CVE-2014-5214: Medium severity micro focus netiq access manager vulnerability
nps/servlet/webacc in iManager in the Administration Console server in NetIQ Access Manager (NAM) 4.x before 4.0.1 HF3 allows remote authenticated novlwww users to read arbitrary files via a query parameter containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-5214?
CVE-2014-5214 is classified as a medium severity vulnerability that allows unauthorized file read access.
How do I fix CVE-2014-5214?
To mitigate CVE-2014-5214, upgrade to NetIQ Access Manager version 4.0.1 HF3 or later.
What types of attacks are possible with CVE-2014-5214?
CVE-2014-5214 enables attackers to exploit XML external entity (XXE) injection vulnerabilities to read arbitrary files.
Who is affected by CVE-2014-5214?
CVE-2014-5214 affects users of NetIQ Access Manager versions 4.0 and 4.0.1 prior to HF3.
Is authentication required to exploit CVE-2014-5214?
Yes, exploitation of CVE-2014-5214 requires authentication as the vulnerability targets remote authenticated novlwww users.