Описание
NetIQ Access Manager (NAM) 4.x before 4.0.1 HF3 allows remote authenticated administrators to discover service-account passwords via a request to (1) roma/jsp/volsc/monitoring/dev_services.jsp or (2) roma/jsp/debug/debug.jsp.
Ссылки
- Exploit
- Exploit
- ExploitVendor Advisory
- Exploit
- Exploit
- Exploit
- ExploitVendor Advisory
- Exploit
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:microfocus:access_manager:4.0:*:*:*:*:*:*:*
cpe:2.3:a:microfocus:access_manager:4.0.1:*:*:*:*:*:*:*
EPSS
Процентиль: 58%
0.00359
Низкий
4 Medium
CVSS2
Дефекты
CWE-200
Связанные уязвимости
github
больше 3 лет назад
NetIQ Access Manager (NAM) 4.x before 4.0.1 HF3 allows remote authenticated administrators to discover service-account passwords via a request to (1) roma/jsp/volsc/monitoring/dev_services.jsp or (2) roma/jsp/debug/debug.jsp.
EPSS
Процентиль: 58%
0.00359
Низкий
4 Medium
CVSS2
Дефекты
CWE-200