CVE-2017-14803: Critical severity micro focus netiq access manager vulnerability
Published Jan 20, 2018
·Updated
In NetIQ Access Manager 4.3 and 4.4, a bug exists in Identity Server when accessing a basic SSO connector and downloading the BasicSSO connector plugins on IE11 where an attacker can execute arbitrary code on the system.
Affected Software
2 affected components
NetIQ Access Manager=4.3
NetIQ Access Manager=4.4
Event History
Jan 20, 2018
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-14803?
CVE-2017-14803 is considered a critical vulnerability due to the potential for arbitrary code execution.
2
How do I fix CVE-2017-14803?
To remediate CVE-2017-14803, update to the latest version of NetIQ Access Manager, ensuring you are on version 4.5 or later.
3
Who is affected by CVE-2017-14803?
CVE-2017-14803 affects users of NetIQ Access Manager versions 4.3 and 4.4 using Internet Explorer 11.
4
What type of attack is associated with CVE-2017-14803?
CVE-2017-14803 allows attackers to exploit vulnerabilities in the BasicSSO connector to execute arbitrary code.
5
Is CVE-2017-14803 currently under active exploitation?
As of now, there have been no confirmed reports of active exploitation of CVE-2017-14803.