CVE-2019-3489: Malicious File Upload
An unauthenticated file upload vulnerability has been identified in the Web Client component of Micro Focus Content Manager 9.1, 9.2, and 9.3 when configured to use the ADFS authentication method. The vulnerability could be exploited by an unauthenticated remote attacker to upload content to arbitrary locations on the Content Manager server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-3489?
CVE-2019-3489 is classified as a critical severity vulnerability due to its potential for unauthenticated remote file uploads.
How do I fix CVE-2019-3489?
To mitigate CVE-2019-3489, upgrade Micro Focus Content Manager to a version higher than 9.3 to ensure the vulnerability is resolved.
Which versions of Micro Focus Content Manager are affected by CVE-2019-3489?
CVE-2019-3489 affects Micro Focus Content Manager versions 9.1, 9.2, and 9.3.
What type of attack does CVE-2019-3489 enable?
CVE-2019-3489 enables an unauthenticated remote attacker to upload arbitrary content to the server.
Is authentication required to exploit CVE-2019-3489?
No, CVE-2019-3489 can be exploited by an unauthenticated attacker, which increases its risk.