Skip to content
COOEY

EXPOSURES › CVE-2021-22506

CVE-2021-22506

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-22506 ↗
⌖ EXPLOITED IN THE WILD SHAME 78/100 exploited-in-wildunpatcheddata-breach

Micro Focus Access Manager leaked sensitive data via a SAML redirection flaw that was actively exploited in the wild.

A SAML service provider redirection issue in Micro Focus Access Manager allowed information leakage when the Assertion Consumer Service URL was used. This unpatched vulnerability was added to CISA's KEV catalog, indicating it was actively exploited in the wild, posing a significant data exposure risk for organizations relying on this identity management solution. DIB organizations should verify their identity management vendors for known KEV vulnerabilities and ensure all software is patched to prevent data breaches.

Shame score — The vulnerability was actively exploited in the wild and added to CISA's KEV catalog, indicating a severe, avoidable failure to patch a known issue that led to data leakage.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Micro Focus Access Manager contains an information leakage vulnerability resulting from a SAML service provider redirection issue when the Assertion Consumer Service URL is used.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.80
Vulnerability confirmed in critical SAML component, indicating significant security oversight.
cooey ↗ severe-fallout -0.80
Vulnerability confirmed in critical SAML component, indicating significant security oversight.
"Micro Focus Access Manager contains an information leakage vulnerability resulting from a SAML service provider redirection issue when the Assertion Consumer Service URL is used."
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.