NetIQ Access Manager 4.1 before 4.1.2 HF 1 and 4.2 before 4.2.2 was parsing incoming SAML requests with external entity resolution enabled, which could lead to local file disclosure via an XML External Entity (XXE) attack.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.novell.com/support/kb/doc.php?id=7017806 |
|
History
No history.
Status: PUBLISHED
Assigner: microfocus
Published: 2017-03-23T06:36:00.000Z
Updated: 2024-08-06T01:07:59.961Z
Reserved: 2016-06-23T00:00:00.000Z
Link: CVE-2016-5749
No data.
Status : Deferred
Published: 2017-03-23T06:59:00.297
Modified: 2025-04-20T01:37:25.860
Link: CVE-2016-5749
No data.