PT-2012-6203 · Netiq · Netiq Privileged User Manager

Published

2012-12-24

·

Updated

2021-04-13

·

CVE-2012-5931

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions NetIQ Privileged User Manager versions 2.3.x through 2.3.1 before HF2
Description The issue allows remote authenticated users to create or overwrite arbitrary files via directory traversal sequences in a log pathname in the set log config function in regclnt.dll in unifid.exe.
Recommendations For versions 2.3.x through 2.3.1 before HF2, update to version 2.3.1 HF2 to resolve the issue.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-5931

Affected Products

Netiq Privileged User Manager