CVE-2017-9280: Netiq Identity Manager
High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.
Some NetIQ Identity Manager Applications before Identity Manager 4.5.6.1 included the session token in GET URLs, potentially allowing exposure of user sessions to untrusted third parties via proxies, referer urls or similar.
Affected products
- Netiq Identity Manager: before 4.5.6.1 (fixed in 4.5.6.1)
Published 2018-03-02. Last modified 2026-06-17.