CVE-2018-7677: CSRF in NetIQ Access Manager (NAM) Identity Server component
A CSRF exposure exists in NetIQ Access Manager (NAM) 4.4 Identity Server component.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
NetIQ Access Manager (NAM) Identity Serverto a version that resolves this vulnerability.Fixed in 4.4 SP1
Event History
Frequently Asked Questions
What is the severity of CVE-2018-7677?
CVE-2018-7677 is classified as a medium severity vulnerability due to its Cross-Site Request Forgery (CSRF) exposure.
How do I fix CVE-2018-7677?
To fix CVE-2018-7677, you should apply the latest security patches provided by NetIQ for Access Manager version 4.4.
What components are affected by CVE-2018-7677?
CVE-2018-7677 specifically affects the Identity Server component of NetIQ Access Manager version 4.4.
What kind of attack can be executed through CVE-2018-7677?
CVE-2018-7677 allows attackers to exploit CSRF to perform unauthorized actions on behalf of authenticated users.
Is CVE-2018-7677 present in versions other than 4.4?
No, CVE-2018-7677 is only reported to affect NetIQ Access Manager version 4.4.