CVE-2017-14803: Netiq Access Manager

Critical severity, CVSS 9.8. EPSS: 34.6% chance of exploitation in the next 30 days.

In NetIQ Access Manager 4.3 and 4.4, a bug exists in Identity Server when accessing a basic SSO connector and downloading the BasicSSO connector plugins on IE11 where an attacker can execute arbitrary code on the system.

Affected products

  • Netiq Access Manager: version 4.3 only; version 4.4 only

Published 2018-01-20. Last modified 2026-06-17.