CVE-2020-25839

CRITICAL

NetIQ Identity Manager < 4.8 SP2 HF1 - SQL Injection

Title source: llm
STIX 2.1

Description

NetIQ Identity Manager 4.8 prior to version 4.8 SP2 HF1 are affected by an injection vulnerability. This vulnerability is fixed in NetIQ IdM 4.8 SP2 HF1.

Scores

CVSS v3 9.8
EPSS 0.0051
EPSS Percentile 66.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
microfocus/identity_manager 4.8 (5 CPE variants)
Published Nov 20, 2020
Tracked Since Feb 18, 2026