Skip to main content

Novell iManager Tomcat Remote File Upload Vulnerability

Last Update Date: 28 Jan 2011 Release Date: 4 Oct 2010 5446 Views

RISK: Medium Risk

A vulnerability has been identified in Novell iManager, which could be exploited by remote attackers to take complete control of an affected system. This issue is caused by access and input validation errors in the "nps.jar" web application when handling uploaded files via the "getMultiPartParameters" function, which could allow remote unauthenticated attackers to upload malicious files to a vulnerable server and execute arbitrary code with the privileges of the affected service.


Impact

  • Remote Code Execution

System / Technologies affected

  • Novell iManager version 2.7.3.2 and prior

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

Upgrade to Novell iManager version 2.7.3 ftf3 or later :
http://download.novell.com


Vulnerability Identifier

  • No CVE information is available

Source


Related Link