First published: Fri Mar 02 2018(Updated: )
NetIQ iManager before 3.0.3 delivered a SSL private key in a Java application (JAR file) for authentication to Sentinel, allowing attackers to extract and establish their own connections to the Sentinel appliance.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
NetIQ iManager | =2.7 | |
NetIQ iManager | =2.7.1 | |
NetIQ iManager | =2.7.2 | |
NetIQ iManager | =2.7.3 | |
NetIQ iManager | =2.7.4 | |
NetIQ iManager | =2.7.5 | |
NetIQ iManager | =2.7.6 | |
NetIQ iManager | =2.7.7-p10 | |
NetIQ iManager | =2.7.7-p11 | |
NetIQ iManager | =2.7.7-p4 | |
NetIQ iManager | =2.7.7-p5 | |
NetIQ iManager | =2.7.7-p6 | |
NetIQ iManager | =2.7.7-p7 | |
NetIQ iManager | =2.7.7-p8 | |
NetIQ iManager | =2.7.7-p9 | |
NetIQ iManager | =2.7.7.10-hf1 | |
NetIQ iManager | =2.7.7.10-hf2 | |
NetIQ iManager | =3.0 | |
NetIQ iManager | =3.0-sp1 | |
NetIQ iManager | =3.0-sp2 | |
NetIQ iManager | =3.0-sp3 | |
NetIQ iManager | =3.0-sp4 | |
NetIQ iManager | =3.0.2-p1 | |
NetIQ iManager | =3.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-5189 has a high severity rating due to its potential to expose SSL private keys, leading to unauthorized access to the Sentinel appliance.
To fix CVE-2017-5189, upgrade the affected NetIQ iManager version to 3.0.3 or later.
CVE-2017-5189 affects various versions of NetIQ iManager, specifically versions 2.7, 2.7.x, and 3.0 before 3.0.3.
Yes, CVE-2017-5189 can lead to data breaches as attackers can extract SSL private keys and establish unauthorized connections.
Currently, the recommended solution for CVE-2017-5189 is to apply the appropriate software upgrade rather than relying on a temporary workaround.