CVE-2016-5749

MEDIUM

NetIQ Access Manager <4.1.2-4.2.2 - Info Disclosure

Title source: llm

Description

NetIQ Access Manager 4.1 before 4.1.2 HF 1 and 4.2 before 4.2.2 was parsing incoming SAML requests with external entity resolution enabled, which could lead to local file disclosure via an XML External Entity (XXE) attack.

Scores

CVSS v3 5.5
EPSS 0.0007
EPSS Percentile 21.9%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-611
Status published

Affected Products (6)

netiq/access_manager
netiq/access_manager
netiq/access_manager
netiq/access_manager
netiq/access_manager
n/a/NetIQ Access Manager < NetIQ Access Manager

Timeline

Published Mar 23, 2017
Tracked Since Feb 18, 2026