CVE-2018-1342: Malicious File Upload
Published Jan 26, 2018
·Updated
A Vulnerability exists on Admin Console where an attacker can upload files to the Admin Console server, and potentially execute them. This impacts NetIQ Access Manager versions 4.3 and 4.4 as well as the Administrative console.
Affected Software
2 affected components
NetIQ Access Manager=4.3
NetIQ Access Manager=4.4
Event History
Jan 26, 2018
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-1342?
CVE-2018-1342 is considered a critical vulnerability due to the potential for remote file upload and execution on vulnerable servers.
2
How do I fix CVE-2018-1342?
To fix CVE-2018-1342, upgrade to the latest version of NetIQ Access Manager which addresses this vulnerability.
3
What versions of NetIQ Access Manager are affected by CVE-2018-1342?
CVE-2018-1342 affects NetIQ Access Manager versions 4.3 and 4.4.
4
What type of attack does CVE-2018-1342 allow?
CVE-2018-1342 allows an attacker to upload files and potentially execute them on the Admin Console server.
5
Is there a workaround for CVE-2018-1342?
There are no documented workarounds for CVE-2018-1342; upgrading is the recommended mitigation.