CVE-2016-5757
critical
CVSS v3
9.8
CVSS v2
7.5
VIR risk
9.8
Description
iManager Admin Console in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 was vulnerable to iFrame manipulation attacks, which could allow remote users to gain access to authentication credentials.
Predictions
Exploit likelihood
97%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| netiq | access_manager | 4.1 | |
| netiq | access_manager | 4.2 | |
References
CWEs
CWE-200
Verify integrity in audit chain (admin only). AS-IS.