NetIQ Security Manager "DumpToFile()" Remote Code Execution Vulnerability
Last Update Date:
9 Jul 2014
Release Date:
8 Jul 2014
3664
Views
RISK: Medium Risk
TYPE: Security software and application - Security Software & Appliance
A vulnerability has been identified in NetIQ Security Manager, which can be exploited by malicious people to compromise a user's system.
The vulnerability is caused due to an error in the "DumpToFile()" method within the NQMcsVarSet ActiveX control, which can be exploited to execute arbitrary code by using directory traversal sequences.
Impact
- Remote Code Execution
System / Technologies affected
- Versions prior to 6.5.4 Hotfix 20140606
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Update to version 6.5.4 Hotfix 20140606.
Vulnerability Identifier
Source
Related Link
Share with