CVE-2016-5749: XEE
NetIQ Access Manager 4.1 before 4.1.2 HF 1 and 4.2 before 4.2.2 was parsing incoming SAML requests with external entity resolution enabled, which could lead to local file disclosure via an XML External Entity (XXE) attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5749?
CVE-2016-5749 has been assigned a medium severity rating, indicating potential risks but manageable in most environments.
How do I fix CVE-2016-5749?
To fix CVE-2016-5749, upgrade to NetIQ Access Manager version 4.1.2 HF 1 or 4.2.2 and ensure external entity resolution is disabled.
What types of attacks does CVE-2016-5749 expose systems to?
CVE-2016-5749 exposes systems to XML External Entity (XXE) attacks that can result in local file disclosure.
Which versions of NetIQ Access Manager are affected by CVE-2016-5749?
Versions 4.1 before 4.1.2 HF 1 and 4.2 before 4.2.2 of NetIQ Access Manager are affected by CVE-2016-5749.
What is the primary cause of CVE-2016-5749?
The primary cause of CVE-2016-5749 is the parsing of incoming SAML requests with external entity resolution enabled.