← Vulnerability feed

Vulnerability record · CVE-2017-5189 · published 2 March 2018

CVE-2017-5189: Netiq imanager insufficiently protected credentials vulnerability

Netiq · Imanager

NetIQ iManager before 3.0.3 delivered a SSL private key in a Java application (JAR file) for authentication to Sentinel, allowing attackers to extract and establish their own connections to the Sentinel appliance.

7.5 CVSS 3.0 High EPSS 1.2% · top 33.9% CWE-522 · Insufficiently protected credentialsCWE-287 · Improper authentication
7.5CVSS 3.0 base score, v2 5.0
1.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

NetIQ iManager before 3.0.3 delivered a SSL private key in a Java application (JAR file) for authentication to Sentinel, allowing attackers to extract and establish their own connections to the Sentinel appliance.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-5189 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-7432Novell imanager vulnerabilityNovell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have a webshell upload vulnerability.EPSS 1.5%8.8CVE-2018-1345Netiq imanager vulnerabilityNetIQ iManager, versions prior to 3.1, under some circumstances could be susceptible to an elevation of privilege attack.EPSS 0.65%8.8CVE-2017-7431Novell imanager cross-site request forgery vulnerabilityNovell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have persistent CSRF in object management.EPSS 0.58%8.6CVE-2018-1344Netiq imanager vulnerabilityAddresses potential communication downgrade attack in NetIQ iManager versions prior to 3.1EPSS 0.86%7.5CVE-2017-5186Netiq edirectory broken cryptographic algorithm vulnerabilityNovell iManager 2.7 before SP7 Patch 9, NetIQ iManager 3.x before 3.0.2.1, Novell eDirectory 8.8.x before 8.8 SP8 Patch 9 Hotfix 2, and NetIQ eDirect…EPSS 0.65%6.1CVE-2022-38758Netiq imanager cross-site scripting vulnerabilityCross-site Scripting (XSS) vulnerability in NetIQ iManager prior to version 3.2.6 allows attacker to execute malicious scripts on the user's browser.…EPSS 0.45%6.1CVE-2018-12462Netiq imanager cross-site scripting vulnerabilityNetIQ iManager 3.1.1 addresses potential XSS vulnerabilities.EPSS 0.58%6.1CVE-2018-1347Netiq imanager cross-site scripting vulnerabilityThe administrative web interface in NetIQ iManager, versions prior to 3.1, are vulnerable to reflected cross site scripting.EPSS 0.73%

Source: NIST National Vulnerability Database (record CVE-2017-5189), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.