CVE-2012-5930: Medium severity MicroFocus Privileged User Manager vulnerability
The pamodifyaccounts function in auth.dll in unifid.exe in NetIQ Privileged User Manager 2.3.x before 2.3.1 HF2 does not require authentication for the modifyAccounts method, which allows remote attackers to change the passwords of administrative accounts via a crafted application/x-amf request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-5930?
CVE-2012-5930 is considered a critical vulnerability due to the potential for unauthorized access to administrative accounts.
How does CVE-2012-5930 exploit vulnerabilities in NetIQ Privileged User Manager?
CVE-2012-5930 allows remote attackers to change administrative account passwords without authentication by sending a specially crafted application/x-amf request.
Which versions of NetIQ Privileged User Manager are affected by CVE-2012-5930?
CVE-2012-5930 affects Microfocus Privileged User Manager versions 2.3.0 and 2.3.1 before HF2.
How can I mitigate CVE-2012-5930?
To mitigate CVE-2012-5930, upgrade to NetIQ Privileged User Manager version 2.3.1 HF2 or later.
Are there any known exploits for CVE-2012-5930?
Yes, there are established methods for exploiting CVE-2012-5930, allowing attackers to gain unauthorized control over administrative accounts.