CVE-2016-5749
MEDIUMNetIQ Access Manager <4.1.2-4.2.2 - Info Disclosure
Title source: llmDescription
NetIQ Access Manager 4.1 before 4.1.2 HF 1 and 4.2 before 4.2.2 was parsing incoming SAML requests with external entity resolution enabled, which could lead to local file disclosure via an XML External Entity (XXE) attack.
Scores
CVSS v3
5.5
EPSS
0.0007
EPSS Percentile
21.9%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Classification
CWE
CWE-611
Status
published
Affected Products (6)
netiq/access_manager
netiq/access_manager
netiq/access_manager
netiq/access_manager
netiq/access_manager
n/a/NetIQ Access Manager
< NetIQ Access Manager
Timeline
Published
Mar 23, 2017
Tracked Since
Feb 18, 2026