CVE-2024-4555

HIGH

OpenText NetIQ Access Manager < 5.0.4.1 and < 5.1 - User Account Impersonation

Title source: llm
STIX 2.1

Description

Improper Privilege Management vulnerability in OpenText NetIQ Access Manager allows user account impersonation in specific scenario. This issue affects NetIQ Access Manager before 5.0.4.1 and before 5.1

Scores

CVSS v3 7.7
EPSS 0.0026
EPSS Percentile 49.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-269 CWE-266
Status published
Products (1)
microfocus/netiq_access_manager < 5.0.4.1
Published Aug 28, 2024
Tracked Since Feb 18, 2026