CVE-2017-14802: Unvalidated Redirect in NetIQ Access Manager after upgrading to NAM 4.3 AC and IDP URLs
Published Mar 2, 2018
·Updated
Novell Access Manager Admin Console and IDP servers before 4.3.3 have a URL that could be used by remote attackers to trigger unvalidated redirects to third party sites.
Affected Software
1 affected component
NetIQ Access Manager<=4.3
Event History
Mar 2, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-14802?
CVE-2017-14802 is classified as a moderate severity vulnerability due to potential unauthorized access risks.
2
How do I fix CVE-2017-14802?
To mitigate CVE-2017-14802, upgrade Novell Access Manager to version 4.3.3 or later.
3
Who is affected by CVE-2017-14802?
CVE-2017-14802 affects users of Novell Access Manager versions prior to 4.3.3.
4
What type of attack does CVE-2017-14802 allow?
CVE-2017-14802 allows remote attackers to perform unvalidated redirects to third-party sites.
5
Is there a workaround for CVE-2017-14802?
There is no reported workaround for CVE-2017-14802; upgrading to the latest version is recommended.