Novell Access Manager Administration Console File Upload Vulnerability
RISK: Medium Risk
A vulnerability has been identified in Novell Access Manager, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by access and input validation errors in the "PortalModuleInstallManager" component within the Admin Console on Windows when handling uploaded files, which could allow remote unauthenticated attackers to upload malicious files to a vulnerable server via directory traversal attacks and execute arbitrary code with the privileges of the affected service.
Impact
- Remote Code Execution
System / Technologies affected
- Novell Access Manager version 3.1 SP1 (Support Pack 1) and prior
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
Upgrade to Access Manager version 3.1 Support Pack 2 (build 3.1.2-281 or later).
Vulnerability Identifier
Source
Related Link
Share with