Unauthorized Access Vulnerability in NetIQ Privileged User Manager
CVE-2012-5930

Currently unrated

Key Information:

Vendor

Microfocus

Vendor
CVE Published:
24 December 2012

What is CVE-2012-5930?

The pa_modify_accounts function in auth.dll within unifid.exe in NetIQ Privileged User Manager versions 2.3.x before 2.3.1 HF2 lacks proper authentication checks for the modifyAccounts method. This vulnerability enables remote attackers to execute crafted application/x-amf requests, allowing them to modify the passwords of administrative accounts without needing prior authentication.

References

EPSS Score

7% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.