CVE-2017-5189

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
02/03/2018
Last modified:
07/11/2023

Description

NetIQ iManager before 3.0.3 delivered a SSL private key in a Java application (JAR file) for authentication to Sentinel, allowing attackers to extract and establish their own connections to the Sentinel appliance.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:netiq:imanager:2.7:*:*:*:*:*:*:*
cpe:2.3:a:netiq:imanager:2.7.1:*:*:*:*:*:*:*
cpe:2.3:a:netiq:imanager:2.7.2:*:*:*:*:*:*:*
cpe:2.3:a:netiq:imanager:2.7.3:*:*:*:*:*:*:*
cpe:2.3:a:netiq:imanager:2.7.4:*:*:*:*:*:*:*
cpe:2.3:a:netiq:imanager:2.7.5:*:*:*:*:*:*:*
cpe:2.3:a:netiq:imanager:2.7.6:*:*:*:*:*:*:*
cpe:2.3:a:netiq:imanager:2.7.7:p10:*:*:*:*:*:*
cpe:2.3:a:netiq:imanager:2.7.7:p11:*:*:*:*:*:*
cpe:2.3:a:netiq:imanager:2.7.7:p4:*:*:*:*:*:*
cpe:2.3:a:netiq:imanager:2.7.7:p5:*:*:*:*:*:*
cpe:2.3:a:netiq:imanager:2.7.7:p6:*:*:*:*:*:*
cpe:2.3:a:netiq:imanager:2.7.7:p7:*:*:*:*:*:*
cpe:2.3:a:netiq:imanager:2.7.7:p8:*:*:*:*:*:*
cpe:2.3:a:netiq:imanager:2.7.7:p9:*:*:*:*:*:*