First published: Mon Dec 24 2012(Updated: )
Eval injection vulnerability in the ldapagnt_eval function in ldapagnt.dll in unifid.exe in NetIQ Privileged User Manager 2.3.x before 2.3.1 HF2 allows remote attackers to execute arbitrary Perl code via a crafted application/x-amf request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Micro Focus NetIQ Privileged Access Manager | =2.3.0 | |
Micro Focus NetIQ Privileged Access Manager | =2.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-5932 is considered a high severity vulnerability due to its ability to allow remote code execution.
To fix CVE-2012-5932, update to NetIQ Privileged User Manager version 2.3.1 HF2 or later.
CVE-2012-5932 facilitates remote code execution attacks through crafted application/x-amf requests.
CVE-2012-5932 affects NetIQ Privileged User Manager versions 2.3.0 and 2.3.1 prior to HF2.
Yes, CVE-2012-5932 is exploitable remotely, making it a significant risk if vulnerable systems are exposed to the internet.