CVE-2018-1348: NetIQ Identity Manager SSL Renegotiation
Published Mar 26, 2018
·Updated
NetIQ Identity Manager driver, in versions prior to 4.7, allows for an SSL handshake renegotiation which could result in a MITM attack.
Affected Software
1 affected component
NetIQ Identity Manager<=4.6
Remediation
Information
Upgrade to NetIQ Identity Manager 4.7
Event History
Mar 26, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-1348?
CVE-2018-1348 is considered high severity due to the potential for a Man-in-the-Middle (MITM) attack.
2
How do I fix CVE-2018-1348?
To mitigate CVE-2018-1348, upgrade NetIQ Identity Manager to version 4.7 or later.
3
What versions of NetIQ Identity Manager are affected by CVE-2018-1348?
CVE-2018-1348 affects all versions of NetIQ Identity Manager prior to 4.7.
4
What type of attack does CVE-2018-1348 enable?
CVE-2018-1348 could enable a Man-in-the-Middle (MITM) attack due to SSL handshake renegotiation.
5
Is there a workaround for CVE-2018-1348 if I cannot upgrade?
There are no documented workarounds for CVE-2018-1348, so upgrading remains the best course of action.