« Volver al listado

CVE-2017-7428

Estado: ModificadaMedia (5.3)—

NetIQ iManager 3.x before 3.0.3.1 has an issue in the renegotiation of connection parameters with Tomcat.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-7428",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": true,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@opentext.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "NetIQ iManager 3.x before 3.0.3.1",
          "versions": [
            {
              "status": "affected",
              "version": "NetIQ iManager 3.x before 3.0.3.1"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-05-03T05:59:00.203",
  "references": [
    {
      "url": "https://bugzilla.novell.com/show_bug.cgi?id=1029431",
      "source": "security@opentext.com"
    },
    {
      "url": "https://dl.netiq.com/Download?buildid=wpS1UqIlx-o~",
      "source": "security@opentext.com"
    },
    {
      "url": "https://www.netiq.com/support/kb/doc.php?id=7016795",
      "source": "security@opentext.com"
    },
    {
      "url": "https://bugzilla.novell.com/show_bug.cgi?id=1029431",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://dl.netiq.com/Download?buildid=wpS1UqIlx-o~",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.netiq.com/support/kb/doc.php?id=7016795",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "NetIQ iManager 3.x before 3.0.3.1 has an issue in the renegotiation of connection parameters with Tomcat."
    },
    {
      "lang": "es",
      "value": "NetIQ iManager 3.x antes de 3.0.3.1 tiene un problema en la renegociación de los parámetros de conexión con Tomcat."
    }
  ],
  "lastModified": "2026-06-17T01:24:20.043",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:netiq:imanager:3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5D3D7F7B-CF13-4729-BDC8-FA7C25EB0856"
            },
            {
              "criteria": "cpe:2.3:a:netiq:imanager:3.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8B44FED3-A5D0-4F0D-AD4F-329152057627"
            },
            {
              "criteria": "cpe:2.3:a:netiq:imanager:3.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8A555C67-FE51-414D-B93A-42DEC732EAAA"
            },
            {
              "criteria": "cpe:2.3:a:netiq:imanager:3.0.2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "54F06556-00E1-40B1-97B9-E0574DC4B597"
            },
            {
              "criteria": "cpe:2.3:a:netiq:imanager:3.0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2482872E-C1FE-4E4E-833A-A426CC4E1230"
            },
            {
              "criteria": "cpe:2.3:a:netiq:imanager:3.0.3.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2DDB7A9D-A03D-458D-87CA-EF9440ABA86E"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@opentext.com"
}