CVE-2016-5750: High severity micro focus netiq access manager vulnerability
Published Mar 23, 2017
·Updated
The certificate upload feature in iManager in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 could be used to upload JSP pages that would be executed as the iManager user, allowing code execution by logged-in remote users.
Affected Software
5 affected components
NetIQ Access Manager=4.1
NetIQ Access Manager=4.1-sp1
NetIQ Access Manager=4.1-sp2
NetIQ Access Manager=4.2
NetIQ Access Manager=4.2-sp1
Event History
Mar 23, 2017
CVE Published
via MITRE·06:36 AM
Data Sourced
via MITRE·06:36 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2016-5750?
CVE-2016-5750 has a high severity rating due to the potential for remote code execution.
2
How do I fix CVE-2016-5750?
To fix CVE-2016-5750, upgrade to NetIQ Access Manager version 4.1.2 Hot Fix 1 or 4.2.2.
3
Who is affected by CVE-2016-5750?
CVE-2016-5750 affects users of NetIQ Access Manager versions 4.1 and 4.2 prior to specified updates.
4
What types of exploitations are possible with CVE-2016-5750?
CVE-2016-5750 can be exploited to allow logged-in remote users to execute arbitrary JSP code.
5
What is the impact of CVE-2016-5750?
The impact of CVE-2016-5750 includes unauthorized code execution which can compromise system integrity.