CVE-2017-5189: private SSL key embedded in JAR file in iManager
NetIQ iManager before 3.0.3 delivered a SSL private key in a Java application (JAR file) for authentication to Sentinel, allowing attackers to extract and establish their own connections to the Sentinel appliance.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5189?
CVE-2017-5189 has a high severity rating due to its potential to expose SSL private keys, leading to unauthorized access to the Sentinel appliance.
How do I fix CVE-2017-5189?
To fix CVE-2017-5189, upgrade the affected NetIQ iManager version to 3.0.3 or later.
What software is affected by CVE-2017-5189?
CVE-2017-5189 affects various versions of NetIQ iManager, specifically versions 2.7, 2.7.x, and 3.0 before 3.0.3.
Can CVE-2017-5189 lead to data breaches?
Yes, CVE-2017-5189 can lead to data breaches as attackers can extract SSL private keys and establish unauthorized connections.
Is there a workaround for CVE-2017-5189?
Currently, the recommended solution for CVE-2017-5189 is to apply the appropriate software upgrade rather than relying on a temporary workaround.