NetIQ Access Manager 4.1 before 4.1.2 HF 1 and 4.2 before 4.2.2 was parsing incoming SAML requests with external entity resolution enabled, which could lead to local file disclosure via an XML External Entity (XXE) attack.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 02:54
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.novell.com/support/kb/doc.php?id=7017806 - |
07 Nov 2023, 02:33
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.novell.com/support/kb/doc.php?id=7017806 - |
Information
Published : 2017-03-23 06:59
Updated : 2024-11-21 02:54
NVD link : CVE-2016-5749
Mitre link : CVE-2016-5749
CVE.ORG link : CVE-2016-5749
JSON object : View
Products Affected
netiq
- access_manager
CWE
CWE-611
Improper Restriction of XML External Entity Reference