彙總 NetIQ 相關全部產品的 CVE 與安全漏洞情報,包括 CVSS、EPSS、公開時間與漏洞情報資料。
已披露問題常與 CSRF、XXE與輸入驗證問題 相關,可能在 軟體部署與生產負載 場景中帶來 工作階段劫持與檔案覆寫 等暴露風險。
相關漏洞資料主要來源於公開漏洞披露與安全公告,可用於評估歷史漏洞暴露面與修補優先順序。
| CVE | 摘要 | 來源 | 最高 CVSS | EPSS % | 公開時間 | 更新時間 |
|---|---|---|---|---|---|---|
| CVE-2022-26322 | Possible Insertion of Sensitive Information into Log File Vulnerability in Identity Manager has been discovered in OpenText™ Identity Manager REST Driver. This impact version before 1.1.2.0200. | [email protected] | 4.9 | 0.36% | 2024-09-12 | 2026-06-17 |
| CVE-2020-11843 | This allows the information exposure to unauthorized users. This issue affects NetIQ Access Manager using version 4.5 or before | [email protected] | 6.5 | 0.48% | 2024-06-11 | 2026-06-16 |
| CVE-2024-1470 | Authorization Bypass Through User-Controlled Key vulnerability in NetIQ (OpenText) Client Login Extension on Windows allows Privilege Escalation, Code Injection.This issue only affects NetIQ Client Login Extension: 4.6. | [email protected] | 7.1 | 0.19% | 2024-02-28 | 2026-06-17 |
| CVE-2022-38758 | Cross-site Scripting (XSS) vulnerability in NetIQ iManager prior to version 3.2.6 allows attacker to execute malicious scripts on the user's browser. This issue affects: Micro Focus NetIQ iManager NetIQ iManager versions prior to 3.2.6 on ALL. | [email protected] | 7.2 | 0.37% | 2023-01-26 | 2026-06-17 |
| CVE-2022-26329 | File existence disclosure vulnerability in NetIQ Identity Manager plugin prior to version 4.8.5 allows attacker to determine whether a file exists on the filesystem. This issue affects: Micro Focus NetIQ Identity Manager NetIQ Identity Manager versions prior to 4.8.5 on ALL. | [email protected] | 1.8 | 0.46% | 2023-01-26 | 2026-06-17 |
| CVE-2019-11648 | An information leakage exists in Micro Focus NetIQ Self Service Password Reset Software all versions prior to version 4.4. The vulnerability could be exploited to expose sensitive information. | [email protected] | 7.5 | 1.11% | 2019-06-24 | 2026-06-16 |
| CVE-2018-12462 | NetIQ iManager 3.1.1 addresses potential XSS vulnerabilities. | [email protected] | 4.8 | 0.58% | 2018-07-10 | 2026-06-16 |
| CVE-2018-12461 | Fixed issues with NetIQ eDirectory prior to 9.1.1 when checking certificate revocation. | [email protected] | 3.5 | 0.49% | 2018-07-10 | 2026-06-16 |
| CVE-2017-9284 | IDM 4.6 Identity Applications prior to 4.6.2.1 may expose sensitive information. | [email protected] | 4.8 | 1.28% | 2018-04-26 | 2026-06-16 |
| CVE-2017-9275 | NetIQ Identity Reporting, in versions prior to 5.5 Service Pack 1, is susceptible to an XSS attack. | [email protected] | 2.8 | 0.58% | 2018-04-26 | 2026-06-16 |
| CVE-2018-7676 | The NetIQ Identity Manager, in versions prior to 4.7, userapp with log / trace enabled may leak sensitive information. | [email protected] | 3.9 | 0.86% | 2018-03-28 | 2026-06-16 |
| CVE-2018-7674 | The NetIQ Identity Manager user console, in versions prior to 4.7, is susceptible to URL redirection. | [email protected] | 2.1 | 0.76% | 2018-03-28 | 2026-06-16 |
| CVE-2018-7673 | The NetIQ Identity Manager communication channel, in versions prior to 4.7, is susceptible to a DoS attack. | [email protected] | 5.1 | 0.84% | 2018-03-26 | 2026-06-16 |
| CVE-2018-1350 | The NetIQ Identity Manager driver log file, in versions prior to 4.7, provides details that could aid in system enumeration. | [email protected] | 2.3 | 0.79% | 2018-03-26 | 2026-06-16 |
| CVE-2018-1349 | The NetIQ Identity Manager driver log file, in versions prior to 4.7, provides details that could aid in system or configuration enumeration. | [email protected] | 2.3 | 0.79% | 2018-03-26 | 2026-06-16 |
| CVE-2018-1348 | NetIQ Identity Manager driver, in versions prior to 4.7, allows for an SSL handshake renegotiation which could result in a MITM attack. | [email protected] | 5.3 | 1.06% | 2018-03-26 | 2026-06-16 |
| CVE-2018-1347 | The administrative web interface in NetIQ iManager, versions prior to 3.1, are vulnerable to reflected cross site scripting. | [email protected] | 5.3 | 0.74% | 2018-03-21 | 2026-06-16 |
| CVE-2018-1346 | Addresses denial of service attack to eDirectory versions prior to 9.1. | [email protected] | 3.1 | 1.26% | 2018-03-21 | 2026-06-16 |
| CVE-2018-1345 | NetIQ iManager, versions prior to 3.1, under some circumstances could be susceptible to an elevation of privilege attack. | [email protected] | 5.9 | 0.66% | 2018-03-21 | 2026-06-16 |
| CVE-2018-1344 | Addresses potential communication downgrade attack in NetIQ iManager versions prior to 3.1 | [email protected] | 3.1 | 0.88% | 2018-03-21 | 2026-06-16 |