ZeroHour

CVE-2021-22506

KEVlarge

Information Disclosure via SAML ACS Redirect in Micro Focus Access Manager

CISA: Micro Focus Access Manager Information Leakage Vulnerability

CVSS 3.1
7.5 high
EPSS
26%p98
Published
()
KEV added
AI analysis

Micro Focus Access Manager, an enterprise single sign-on and identity management product (formerly sold as Novell/NetIQ Access Manager), contains an information leakage vulnerability caused by a SAML service provider redirection issue when the Assertion Consumer Service (ACS) URL is used. An attacker who triggers or influences the ACS redirect path can cause SAML sign-in responses or session information to be delivered to an unintended, potentially attacker-controlled destination, exposing sensitive authentication data. The practical gain for an attacker is disclosure of federated sign-in material, which can support session hijacking or user impersonation in SAML-based flows. Any organization running Micro Focus Access Manager in a SAML service provider role is potentially affected; the source data provides no version ranges, so administrators must consult the vendor advisory for affected and fixed releases. The flaw was added to CISA's Known Exploited Vulnerability (KEV) catalog on 2021-11-03, confirming in-the-wild exploitation; no public proof-of-concept is known, CVSS has not yet been scored, and EPSS estimates a 25.7% probability of exploitation within 30 days (98th percentile).

What to do: Apply the Micro Focus update for CVE-2021-22506 per the vendor security bulletin, which is CISA's required action for this KEV entry; since no fixed version numbers are given in the source data, verify your installed Access Manager release against the bulletin before patching. Review whether your deployment acts as a SAML service provider, inspect Assertion Consumer Service URL and redirect handling, and check authentication logs for unexpected redirects or assertion leakage. Treat this as urgent given confirmed in-the-wild exploitation and the elevated EPSS score, even though no public proof-of-concept exists.

Affected
Micro Focus Access Manager
Estimated exposure
largeapproximately tens of thousands of enterprise deployments (order of 10,000-100,000 systems), most running internally with a smaller subset internet-exposed — Access Manager is a two-decade-old enterprise SSO/IAM appliance with a substantial legacy installed base in corporate, education, and government environments; vendor install counts are not published, so this is an order-of-magnitude…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Advance configuration exposing Information Leakage vulnerability in Micro Focus Access Manager product, affects all versions prior to version 5.0. The vulnerability could cause information leakage.

CISA Known Exploited Vulnerability
Affected
Micro Focus Micro Focus Access Manager
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microfocus
Products
access manager
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news