Vulnerability Description
NetIQ iManager before 3.0.3 delivered a SSL private key in a Java application (JAR file) for authentication to Sentinel, allowing attackers to extract and establish their own connections to the Sentinel appliance.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Netiq | Imanager | 2.7 |
Related Weaknesses (CWE)
References
- https://bugzilla.suse.com/show_bug.cgi?id=1021637
- https://www.netiq.com/support/kb/doc.php?id=7016795
- https://bugzilla.suse.com/show_bug.cgi?id=1021637
- https://www.netiq.com/support/kb/doc.php?id=7016795
FAQ
What is CVE-2017-5189?
CVE-2017-5189 is a vulnerability with a CVSS score of 4.3 (MEDIUM). NetIQ iManager before 3.0.3 delivered a SSL private key in a Java application (JAR file) for authentication to Sentinel, allowing attackers to extract and establish their own connections to the Sentin...
How severe is CVE-2017-5189?
CVE-2017-5189 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-5189?
Check the references section above for vendor advisories and patch information. Affected products include: Netiq Imanager.