EXPOSURES › CVE-2021-22506
CVE-2021-22506
HIGH ⌖ ON CISA KEV · EXPLOITEDMicro Focus Access Manager leaked sensitive data via a SAML redirection flaw that was actively exploited in the wild.
A SAML service provider redirection issue in Micro Focus Access Manager allowed information leakage when the Assertion Consumer Service URL was used. This unpatched vulnerability was added to CISA's KEV catalog, indicating it was actively exploited in the wild, posing a significant data exposure risk for organizations relying on this identity management solution. DIB organizations should verify their identity management vendors for known KEV vulnerabilities and ensure all software is patched to prevent data breaches.
Shame score — The vulnerability was actively exploited in the wild and added to CISA's KEV catalog, indicating a severe, avoidable failure to patch a known issue that led to data leakage.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Micro Focus Access Manager contains an information leakage vulnerability resulting from a SAML service provider redirection issue when the Assertion Consumer Service URL is used.
"Micro Focus Access Manager contains an information leakage vulnerability resulting from a SAML service provider redirection issue when the Assertion Consumer Service URL is used."