CVE Published: 20/04/2017 |
CVE Updated: 05/08/2024 |
CVE Year: 2017 Source: microfocus |
Vendor: n/a |
Product: NAM Identity Server and SAML2 Service Provider Status : PUBLISHED
CVE-2017-5190 Description
NetIQ Access Manager 4.2 before SP3 HF1 and 4.3 before SP1 HF1, when configured as a SAML 2.0 Identity Server with Virtual Attributes, has a concurrency issue causing information leakage, related to a stale profile.