Executive brief
Micro Focus Access Manager contains an information leakage vulnerability due to an advanced configuration issue involving SAML service provider redirection when the Assertion Consumer Service URL is used. This flaw allows an unauthenticated remote attacker to potentially access sensitive information.
Affected products
- Micro Focus Access Manager All versions prior to 5.0
Timeline
- 2021-03-26: disclosed: NVD Published Date
- 2021-11-03: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: advisory: External advisory publication date