CVE-2024-3488
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
File Upload vulnerability in unauthenticated
session found in OpenText™ iManager 3.2.6.0200. The vulnerability could allow ant attacker to upload a
file without authentication.
Affected (5)
Products: Microfocus: Imanager
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 3.0 to 3.2.6 |
Related CWEs
CWE-20
Improper Input Validation
The product receives input or data, but it does
not validate or incorrectly validates that the input has the
properties that are required to process the data safely and
correctly.
CWE-434
Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
References (2)
Source: security@opentext.com
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes
Timeline
No history available yet.