CVE-2016-5750
high
CVSS v3
8.8
CVSS v2
6.5
VIR risk
8.8
Description
The certificate upload feature in iManager in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 could be used to upload JSP pages that would be executed as the iManager user, allowing code execution by logged-in remote users.
Predictions
Exploit likelihood
92%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| netiq | access_manager | 4.1 | |
| netiq | access_manager | 4.2 | |
References
CWEs
CWE-284
Verify integrity in audit chain (admin only). AS-IS.