First published: Sat Jan 20 2018(Updated: )
In NetIQ Access Manager 4.3 and 4.4, a bug exists in Identity Server when accessing a basic SSO connector and downloading the BasicSSO connector plugins on IE11 where an attacker can execute arbitrary code on the system.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
Micro Focus NetIQ Access Manager | =4.3 | |
Micro Focus NetIQ Access Manager | =4.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-14803 is considered a critical vulnerability due to the potential for arbitrary code execution.
To remediate CVE-2017-14803, update to the latest version of NetIQ Access Manager, ensuring you are on version 4.5 or later.
CVE-2017-14803 affects users of NetIQ Access Manager versions 4.3 and 4.4 using Internet Explorer 11.
CVE-2017-14803 allows attackers to exploit vulnerabilities in the BasicSSO connector to execute arbitrary code.
As of now, there have been no confirmed reports of active exploitation of CVE-2017-14803.