NetIQ Identity Manager before 4.5.6.1 allowed uploading files with double extensions or non-image content in the Themes handling of the User Application Administration, allowing malicious user administrators to potentially execute code or mislead users.
2018-03-02T20:29:00.910
2024-11-21T03:35:44.793
Modified
CVSSv3.0: 2.0 (LOW)
AV:N/AC:L/Au:S/C:C/I:C/A:C
8.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | netiq | identity_manager | < 4.5.6.1 | Yes |