CVE-2016-5752: Infoleak
The SAML2 implementation in Identity Server in NetIQ Access Manager 4.1 before 4.1.2 HF1 and 4.2 before 4.2.2 was handling unsigned SAML requests incorrectly, leaking results to a potentially malicious "Assertion Consumer Service URL" instead of the original requester.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5752?
CVE-2016-5752 has been assigned a medium severity level due to its potential for unauthorized information disclosure.
How do I fix CVE-2016-5752?
To fix CVE-2016-5752, you should upgrade to NetIQ Access Manager version 4.1.2 HF1 or 4.2.2 or later.
What versions of NetIQ Access Manager are affected by CVE-2016-5752?
Versions 4.1, 4.1 SP1, 4.1 SP2, 4.2, and 4.2 SP1 of NetIQ Access Manager are affected by CVE-2016-5752.
What type of vulnerability is CVE-2016-5752?
CVE-2016-5752 is a security vulnerability related to the handling of unsigned SAML requests.
What is the impact of CVE-2016-5752?
The impact of CVE-2016-5752 is the leakage of results to a potentially malicious "Assertion Consumer Service URL" instead of the legitimate requestor.