First published: Fri Mar 02 2018(Updated: )
NetIQ iManager before 3.0.3 delivered a SSL private key in a Java application (JAR file) for authentication to Sentinel, allowing attackers to extract and establish their own connections to the Sentinel appliance.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
NetIQ iManager | =2.7 | |
NetIQ iManager | =2.7.1 | |
NetIQ iManager | =2.7.2 | |
NetIQ iManager | =2.7.3 | |
NetIQ iManager | =2.7.4 | |
NetIQ iManager | =2.7.5 | |
NetIQ iManager | =2.7.6 | |
NetIQ iManager | =2.7.7-p10 | |
NetIQ iManager | =2.7.7-p11 | |
NetIQ iManager | =2.7.7-p4 | |
NetIQ iManager | =2.7.7-p5 | |
NetIQ iManager | =2.7.7-p6 | |
NetIQ iManager | =2.7.7-p7 | |
NetIQ iManager | =2.7.7-p8 | |
NetIQ iManager | =2.7.7-p9 | |
NetIQ iManager | =2.7.7.10-hf1 | |
NetIQ iManager | =2.7.7.10-hf2 | |
NetIQ iManager | =3.0 | |
NetIQ iManager | =3.0-sp1 | |
NetIQ iManager | =3.0-sp2 | |
NetIQ iManager | =3.0-sp3 | |
NetIQ iManager | =3.0-sp4 | |
NetIQ iManager | =3.0.2-p1 | |
NetIQ iManager | =3.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.