PT-2012-6204 · Netiq · Netiq Privileged User Manager

Publicado

2012-12-24

·

Atualizado

2021-04-13

·

CVE-2012-5932

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions NetIQ Privileged User Manager versions 2.3.x through 2.3.1 before HF2
Description The issue allows remote attackers to execute arbitrary Perl code via a crafted application/x-amf request. This is due to an eval injection vulnerability in the ldapagnt eval function in ldapagnt.dll in unifid.exe.
Recommendations For versions 2.3.x through 2.3.1 before HF2, update to version 2.3.1 HF2 to resolve the issue. As a temporary workaround, consider restricting access to the ldapagnt eval function in ldapagnt.dll to minimize the risk of exploitation.

Exploit

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-5932

Produtos afetados

Netiq Privileged User Manager