CVE-2014-5215: Infoleak
NetIQ Access Manager (NAM) 4.x before 4.0.1 HF3 allows remote authenticated administrators to discover service-account passwords via a request to (1) roma/jsp/volsc/monitoring/devservices.jsp or (2) roma/jsp/debug/debug.jsp.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-5215?
CVE-2014-5215 is classified as a moderate severity vulnerability due to the potential for sensitive information disclosure.
How do I fix CVE-2014-5215?
To fix CVE-2014-5215, upgrade to NetIQ Access Manager version 4.0.1 HF3 or later.
Who is affected by CVE-2014-5215?
CVE-2014-5215 affects NetIQ Access Manager versions 4.0 and 4.0.1 before HF3.
What type of vulnerability is CVE-2014-5215?
CVE-2014-5215 is a disclosure vulnerability that allows authenticated users to access sensitive service-account passwords.
What are the potential consequences of CVE-2014-5215?
The potential consequences of CVE-2014-5215 include unauthorized access to sensitive credentials, leading to further attacks against the system.