CVE-2017-5190: Netiq Access Manager

Low severity, CVSS 3.1. EPSS: 0.7% chance of exploitation in the next 30 days.

NetIQ Access Manager 4.2 before SP3 HF1 and 4.3 before SP1 HF1, when configured as a SAML 2.0 Identity Server with Virtual Attributes, has a concurrency issue causing information leakage, related to a stale profile.

Affected products

  • Netiq Access Manager: up to and including 4.2; up to and including 4.3

Published 2017-04-20. Last modified 2026-06-17.