CVE-2017-5189

NetIQ iManager before 3.0.3 delivered a SSL private key in a Java application (JAR file) for authentication to Sentinel, allowing attackers to extract and establish their own connections to the Sentinel appliance.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
microfocusCNA
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 40%
VendorProductVersion
netiqimanager
2.7
netiqimanager
2.7.1
netiqimanager
2.7.2
netiqimanager
2.7.3
netiqimanager
2.7.4
netiqimanager
2.7.5
netiqimanager
2.7.6
netiqimanager
2.7.7:p10
netiqimanager
2.7.7:p11
netiqimanager
2.7.7:p4
netiqimanager
2.7.7:p5
netiqimanager
2.7.7:p6
netiqimanager
2.7.7:p7
netiqimanager
2.7.7:p8
netiqimanager
2.7.7:p9
netiqimanager
2.7.7.10:hf1
netiqimanager
2.7.7.10:hf2
netiqimanager
3.0
netiqimanager
3.0:sp1
netiqimanager
3.0:sp2
netiqimanager
3.0:sp3
netiqimanager
3.0:sp4
netiqimanager
3.0.2:p1
netiqimanager
3.0.3
𝑥
= Vulnerable software versions