Access Manager Netiq Access Manager

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Netiq Access Manager.

By the Year

In 2026 there have been 0 vulnerabilities in Netiq Access Manager. Access Manager did not have any published security vulnerabilities last year.

Year Vulnerabilities Average Score
2026 0 0.00
2025 0 0.00
2024 3 7.17
2023 0 0.00
2022 0 0.00
2021 0 0.00
2020 0 0.00
2019 0 0.00
2018 9 9.80

It may take a day or so for new Access Manager vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Netiq Access Manager Security Vulnerabilities

OpenText NetIQ Access Manager 5.1 XSS via Improper Input Validation
CVE-2024-4554 7.3 - High - August 28, 2024

Improper Input Validation vulnerability in OpenText NetIQ Access Manager leads to Cross-Site Scripting (XSS) attack. This issue affects Access Manager before 5.0.4.1 and 5.1.

XSS

NetIQ Access Manager Impostor Privilege Escalation (Before 5.1)
CVE-2024-4555 7.7 - High - August 28, 2024

Improper Privilege Management vulnerability in OpenText NetIQ Access Manager allows user account impersonation in specific scenario. This issue affects NetIQ Access Manager before 5.0.4.1 and before 5.1

Incorrect Privilege Assignment

NetIQ Access Manager <=4.5 Info Exposure to Unauthorized Users
CVE-2020-11843 6.5 - Medium - June 11, 2024

This allows the information exposure to unauthorized users. This issue affects NetIQ Access Manager using version 4.5 or before

A CSRF exposure exists in NetIQ Access Manager (NAM) 4.4 Identity Server component.
CVE-2018-7677 - March 14, 2018

A CSRF exposure exists in NetIQ Access Manager (NAM) 4.4 Identity Server component.

A cross site scripting vulnerability exist in the Administration Console in NetIQ Access Manager (NAM) 4.3 and 4.4.
CVE-2018-7678 - March 14, 2018

A cross site scripting vulnerability exist in the Administration Console in NetIQ Access Manager (NAM) 4.3 and 4.4.

Reflected XSS in the NetIQ Access Manager before 4.3.3
CVE-2017-14801 - March 02, 2018

Reflected XSS in the NetIQ Access Manager before 4.3.3 allowed attackers to reflect back xss into the called page using the url parameter.

XSS

Novell Access Manager Admin Console and IDP servers before 4.3.3 have a URL
CVE-2017-14802 - March 02, 2018

Novell Access Manager Admin Console and IDP servers before 4.3.3 have a URL that could be used by remote attackers to trigger unvalidated redirects to third party sites.

Open Redirect

A OAuth application in NetIQ Access Manager 4.3 before 4.3.2 and 4.2 before 4.2.4 allowed cross site scripting attacks due to unescaped "description" field
CVE-2017-7419 - March 02, 2018

A OAuth application in NetIQ Access Manager 4.3 before 4.3.2 and 4.2 before 4.2.4 allowed cross site scripting attacks due to unescaped "description" field that could be specified by the provider.

XSS

Novell Access Manager iManager before 4.3.3 did not validate parameters so
CVE-2017-9276 - March 02, 2018

Novell Access Manager iManager before 4.3.3 did not validate parameters so that cross site scripting content could be reflected back into the result page using the "a" parameter.

XSS

A cross site scripting attack in handling the ESP login parameter handling in NetIQ Access Manager before 4.3.3 could be used to inject javascript code into the login page.
CVE-2017-14799 - March 01, 2018

A cross site scripting attack in handling the ESP login parameter handling in NetIQ Access Manager before 4.3.3 could be used to inject javascript code into the login page.

A reflected cross site scripting attack in the NetIQ Access Manager before 4.3.3 using the "typecontainerid" parameter of the policy editor could
CVE-2017-14800 - March 01, 2018

A reflected cross site scripting attack in the NetIQ Access Manager before 4.3.3 using the "typecontainerid" parameter of the policy editor could allowed code injection into pages of authenticated users.

A Vulnerability exists on Admin Console where an attacker can upload files to the Admin Console server, and potentially execute them
CVE-2018-1342 9.8 - Critical - January 26, 2018

A Vulnerability exists on Admin Console where an attacker can upload files to the Admin Console server, and potentially execute them. This impacts NetIQ Access Manager versions 4.3 and 4.4 as well as the Administrative console.

Unrestricted File Upload

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Netiq Access Manager or by Netiq? Click the Watch button to subscribe.

Netiq
Vendor

subscribe