NetIQ Access Manager CVE-2018-1342 Arbitrary File Upload Vulnerability
BID:102835
Info
NetIQ Access Manager CVE-2018-1342 Arbitrary File Upload Vulnerability
| Bugtraq ID: | 102835 |
| Class: | Input Validation Error |
| CVE: |
CVE-2018-1342 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 08 2017 12:00AM |
| Updated: | Dec 08 2017 12:00AM |
| Credit: | Ariele Caltabiano (kimiya) and rgod |
| Vulnerable: |
NetIQ Access Manager 4.4 NetIQ Access Manager 4.3 |
| Not Vulnerable: |
NetIQ Access Manager 4.4.0 HF1 NetIQ Access Manager 4.3.3 |
Discussion
NetIQ Access Manager CVE-2018-1342 Arbitrary File Upload Vulnerability
NetIQ Access Manager is prone to an arbitrary file-upload vulnerability.
An attacker may leverage this issue to upload arbitrary files to the affected server; this can result in arbitrary code execution within the context of the vulnerable application.
NetIQ Access Manager 4.3 and 4.4 are vulnerable; other versions may also be affected.
NetIQ Access Manager is prone to an arbitrary file-upload vulnerability.
An attacker may leverage this issue to upload arbitrary files to the affected server; this can result in arbitrary code execution within the context of the vulnerable application.
NetIQ Access Manager 4.3 and 4.4 are vulnerable; other versions may also be affected.
Exploit / POC
NetIQ Access Manager CVE-2018-1342 Arbitrary File Upload Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
NetIQ Access Manager CVE-2018-1342 Arbitrary File Upload Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
NetIQ Access Manager CVE-2018-1342 Arbitrary File Upload Vulnerability
References:
References:
- NetGain Systems Homepage (NetGain Systems)
- Unrestricted File Upload Remote Code Execution Vulnerability in Admin Console (C (Novell)