Some NetIQ Identity Manager Applications before Identity Manager 4.5.6.1 included the session token in GET URLs, potentially allowing exposure of user sessions to untrusted third parties via proxies, referer urls or similar.
References
Link | Resource |
---|---|
https://download.novell.com/Download?buildid=K7lbPAGJyIk~ | Vendor Advisory |
https://bugzilla.suse.com/show_bug.cgi?id=1049143 | Issue Tracking Permissions Required Third Party Advisory |
Configurations
Information
Published : 2018-03-02 12:29
Updated : 2019-10-09 16:30
NVD link : CVE-2017-9280
Mitre link : CVE-2017-9280
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
netiq
- identity_manager