8.8

CVE-2017-7429

Fix for NetIQ shell code upload

The certificate upload in NetIQ eDirectory PKI plugin before 8.8.8 Patch 10 Hotfix 1 could be abused to upload JSP code which could be used by authenticated attackers to execute JSP applets on the iManager server.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microfocus ≫ Edirectory Version <= 8.8.8
Netiq ≫ Edirectory Version 8.8.8 Update patch10
Netiq ≫ Edirectory Version 8.8.8 Update patch5
Netiq ≫ Edirectory Version 8.8.8 Update patch6
Netiq ≫ Edirectory Version 8.8.8 Update patch7
Netiq ≫ Edirectory Version 8.8.8 Update patch8
Netiq ≫ Edirectory Version 8.8.8 Update patch9
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.84% 0.545
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
OpenText 8.8 2.8 5.9
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-295 Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.

CWE-434 Unrestricted Upload of File with Dangerous Type

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

https://www.novell.com/support/kb/doc.php?id=3426981
https://bugzilla.suse.com/show_bug.cgi?id=1024957
https://www.netiq.com/documentation/edir88/edir88810hf1_releasenotes/data/edir88810hf1_releasenotes.html