CVE-2017-5190: Infoleak
NetIQ Access Manager 4.2 before SP3 HF1 and 4.3 before SP1 HF1, when configured as a SAML 2.0 Identity Server with Virtual Attributes, has a concurrency issue causing information leakage, related to a stale profile.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5190?
CVE-2017-5190 is considered a medium severity vulnerability due to its information leakage risk.
How do I fix CVE-2017-5190?
To fix CVE-2017-5190, upgrade NetIQ Access Manager to version 4.2 SP3 HF1 or 4.3 SP1 HF1 or later.
What causes CVE-2017-5190 vulnerability?
CVE-2017-5190 is caused by a concurrency issue that leads to stale profile information leakage in SAML 2.0 Identity Server configurations.
Which versions of NetIQ Access Manager are affected by CVE-2017-5190?
NetIQ Access Manager versions 4.2 before SP3 HF1 and 4.3 before SP1 HF1 are affected by CVE-2017-5190.
Is CVE-2017-5190 a potential risk for my organization's data?
Yes, CVE-2017-5190 poses a risk of exposing sensitive information due to the information leakage vulnerability.