CVE-2021-22524: Denial of service vulnerability in NetIQ Access Manager versions prior to version 4.5.4 and 5.0.1
Published Sep 13, 2021
·Updated
Injection attack caused the denial of service vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4
Affected Software
2 affected components
MicroFocus Access Manager>=4.5.0<4.5.4
MicroFocus Access Manager>=5.0<5.0.1
Remediation
Patch Available
Event History
Sep 13, 2021
CVE Published
via MITRE·11:58 AM
Data Sourced
via MITRE·11:58 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-22524?
CVE-2021-22524 is a vulnerability in NetIQ Access Manager prior to version 5.0.1 and 4.5.4 that allows injection attacks causing denial of service.
2
How can the injection attack vulnerability in NetIQ Access Manager be exploited?
The injection attack vulnerability in NetIQ Access Manager can be exploited by sending specially crafted input that can trigger the denial of service.
3
What is the severity of CVE-2021-22524?
CVE-2021-22524 has a severity rating of medium (4.9).
4
Which versions of NetIQ Access Manager are affected by CVE-2021-22524?
NetIQ Access Manager versions prior to 5.0.1 and 4.5.4 are affected by CVE-2021-22524.
5
How can I fix the injection attack vulnerability in NetIQ Access Manager?
To fix the injection attack vulnerability in NetIQ Access Manager, update to version 5.0.1 or 4.5.4.