9.8
CVE-2024-3969
- EPSS 1.55%
- Veröffentlicht 28.05.2024 15:15:09
- Zuletzt bearbeitet 21.01.2025 17:46:17
- Quelle security@opentext.com
- CVE-Watchlists
- Unerledigt
XML External Entity injection vulnerability found in OpenText™ iManager 3.2.6.0200. This could lead to remote code execution by parsing untrusted XML payload
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microfocus ≫ Imanager Version >= 3.0 < 3.2.6
Microfocus ≫ Imanager Version3.2.6 Update-
Microfocus ≫ Imanager Version3.2.6 Updatepatch1
Microfocus ≫ Imanager Version3.2.6 Updatepatch2
Microfocus ≫ Imanager Version3.2.6 Updatepatch3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.55% | 0.809 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| security@opentext.com | 7.8 | 1.1 | 6 |
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
|
CWE-611 Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.