CVE-2014-5217: Micro Focus Access Manager

Medium severity, CVSS 6.8. EPSS: 1.4% chance of exploitation in the next 30 days.

Cross-site request forgery (CSRF) vulnerability in nps/servlet/webacc in the Administration Console server in NetIQ Access Manager (NAM) 4.x before 4.1 allows remote attackers to hijack the authentication of administrators for requests that change the administrative password via an fw.SetPassword action.

Affected products

  • Micro Focus Access Manager: version 4.0 only; version 4.0.1 only

Published 2014-12-23. Last modified 2026-06-17.