PT-2018-11814 · Netiq · Admin Console+1

Published

2018-01-26

·

Updated

2018-02-13

·

CVE-2018-1342

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NetIQ Access Manager versions 4.3 through 4.4 Administrative console (affected versions not specified)
Description A vulnerability exists in the Admin Console, allowing an attacker to upload files to the Admin Console server and potentially execute them.
Recommendations For NetIQ Access Manager versions 4.3 through 4.4, update to a version that contains a fix for this issue. For the Administrative console, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-1342
ZDI-18-145

Affected Products

Admin Console
Netiq Access Manager