RULE(RULE ID:321885)

Rule General Information
Release Date: 2019-06-20
Rule Name: NetIQ Access Manager Identity Server Directory Traversal Vulnerability (CVE-2017-14803)
Severity:
CVE ID:
Rule Protection Details
Description: In NetIQ Access Manager 4.3 and 4.4, a bug exists in Identity Server when accessing a basic SSO connector and downloading the BasicSSO connector plugins on IE11 where an attacker can execute arbitrary code on the system.
Impact: An attacker can abtain sensitive information of the target victim, and do malicious actions to gain profits using the information.
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others
Reference: https://www.novell.com/support/kb/doc.php?id=7022443
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://www.netiq.com