CVE-2021-22506
KEVlargeInformation Disclosure via SAML ACS Redirect in Micro Focus Access Manager
CISA: Micro Focus Access Manager Information Leakage Vulnerability
Micro Focus Access Manager, an enterprise single sign-on and identity management product (formerly sold as Novell/NetIQ Access Manager), contains an information leakage vulnerability caused by a SAML service provider redirection issue when the Assertion Consumer Service (ACS) URL is used. An attacker who triggers or influences the ACS redirect path can cause SAML sign-in responses or session information to be delivered to an unintended, potentially attacker-controlled destination, exposing sensitive authentication data. The practical gain for an attacker is disclosure of federated sign-in material, which can support session hijacking or user impersonation in SAML-based flows. Any organization running Micro Focus Access Manager in a SAML service provider role is potentially affected; the source data provides no version ranges, so administrators must consult the vendor advisory for affected and fixed releases. The flaw was added to CISA's Known Exploited Vulnerability (KEV) catalog on 2021-11-03, confirming in-the-wild exploitation; no public proof-of-concept is known, CVSS has not yet been scored, and EPSS estimates a 25.7% probability of exploitation within 30 days (98th percentile).
What to do: Apply the Micro Focus update for CVE-2021-22506 per the vendor security bulletin, which is CISA's required action for this KEV entry; since no fixed version numbers are given in the source data, verify your installed Access Manager release against the bulletin before patching. Review whether your deployment acts as a SAML service provider, inspect Assertion Consumer Service URL and redirect handling, and check authentication logs for unexpected redirects or assertion leakage. Treat this as urgent given confirmed in-the-wild exploitation and the elevated EPSS score, even though no public proof-of-concept exists.
| Micro Focus Access Manager | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Advance configuration exposing Information Leakage vulnerability in Micro Focus Access Manager product, affects all versions prior to version 5.0. The vulnerability could cause information leakage.
- Affected
- Micro Focus Micro Focus Access Manager
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microfocus
- Products
- access manager
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N