Skip to main content

NetIQ Security Manager "DumpToFile()" Remote Code Execution Vulnerability

Last Update Date: 9 Jul 2014 Release Date: 8 Jul 2014 3664 Views

RISK: Medium Risk

TYPE: Security software and application - Security Software & Appliance

TYPE: Security Software & Appliance

A vulnerability has been identified in NetIQ Security Manager, which can be exploited by malicious people to compromise a user's system.

The vulnerability is caused due to an error in the "DumpToFile()" method within the NQMcsVarSet ActiveX control, which can be exploited to execute arbitrary code by using directory traversal sequences.


Impact

  • Remote Code Execution

System / Technologies affected

  • Versions prior to 6.5.4 Hotfix 20140606

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Update to version 6.5.4 Hotfix 20140606.

Vulnerability Identifier


Source


Related Link