Loading
NetIQ iManager before 3.0.3 delivered a SSL private key in a Java application (JAR file) for authentication to Sentinel, allowing attackers to extract and establish their own connections to the Sentinel appliance.
Use CWE-522, Netiq vendor hub and Imanager product page to widen CVE-2017-5189 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2017-7432, CVE-2017-7431 and CVE-2017-7425 for nearby disclosures in the same product family.