Injection Vulnerability in NetIQ Identity Manager by Micro Focus
CVE-2020-25839

9.8CRITICAL

Key Information:

Vendor

Microfocus

Vendor
CVE Published:
20 November 2020

What is CVE-2020-25839?

An injection vulnerability exists in NetIQ Identity Manager versions prior to 4.8 SP2 HF1. This flaw could allow malicious actors to execute unauthorized commands or access sensitive data, emphasizing the importance of updating to secure versions to mitigate potential risks.

Affected Version(s)

NetIQ Identity Manager All versions in the 4.8 line prior to version 4.8 Service Pack 2 HotFix 1

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.