IDM 4.6 Identity Applications prior to 4.6.2.1 may expose sensitive information.
The NetIQ Identity Manager communication channel, in versions prior to 4.7, is susceptible to a DoS attack.
NetIQ Identity Manager driver, in versions prior to 4.7, allows for an SSL handshake renegotiation which could result in a MITM attack.
The NetIQ Identity Manager user console, in versions prior to 4.7, is susceptible to URL redirection.
The NetIQ Identity Manager, in versions prior to 4.7, userapp with log / trace enabled may leak sensitive information.
The NetIQ Identity Manager driver log file, in versions prior to 4.7, provides details that could aid in system or configuration enumeration.
The NetIQ Identity Manager driver log file, in versions prior to 4.7, provides details that could aid in system enumeration.