CVE-2014-5217
NetIQ Access Manager 4.x < 4.1 - Cross-Site Request Forgery via Administration Console
Title source: llmDescription
Cross-site request forgery (CSRF) vulnerability in nps/servlet/webacc in the Administration Console server in NetIQ Access Manager (NAM) 4.x before 4.1 allows remote attackers to hijack the authentication of administrators for requests that change the administrative password via an fw.SetPassword action.
References (4)
Core 4
Core References
Exploit mailing-list
x_refsource_fulldisc
http://seclists.org/fulldisclosure/2014/Dec/78
Exploit, Vendor Advisory x_refsource_confirm
https://www.novell.com/support/kb/doc.php?id=7015997
Scores
EPSS
0.0019
EPSS Percentile
40.5%
Details
CWE
CWE-352
Status
published
Products (2)
microfocus/access_manager
4.0
microfocus/access_manager
4.0.1
Published
Dec 23, 2014
Tracked Since
Feb 18, 2026