Lucene search

K
vulnrichmentOpenTextVULNRICHMENT:CVE-2024-3967
HistoryMay 15, 2024 - 4:40 p.m.

CVE-2024-3967 Remote Code Execution vulnerability in the iManager

2024-05-1516:40:10
CWE-502
OpenText
github.com
5
cve-2024-3967
imanager
remote code execution
opentext
java object deserialization

CVSS3

7.6

Attack Vector

ADJACENT

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H

AI Score

8

Confidence

Low

EPSS

0

Percentile

9.0%

SSVC

Exploitation

none

Automatable

no

Technical Impact

total

Remote Code
Execution has been discovered in
OpenText™ iManager 3.2.6.0200. The vulnerability can
trigger remote code execution unisng unsafe java object deserialization.

ADP Affected

[
  {
    "cpes": [
      "cpe:2.3:a:opentext:imanager:*:*:*:*:*:*:*:*"
    ],
    "vendor": "opentext",
    "product": "imanager",
    "versions": [
      {
        "status": "affected",
        "version": "3.2.6.0200"
      }
    ],
    "defaultStatus": "unknown"
  }
]

CVSS3

7.6

Attack Vector

ADJACENT

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H

AI Score

8

Confidence

Low

EPSS

0

Percentile

9.0%

SSVC

Exploitation

none

Automatable

no

Technical Impact

total

Related for VULNRICHMENT:CVE-2024-3967