CVE-2020-25839: SQL Injection
Published Nov 20, 2020
·Updated
NetIQ Identity Manager 4.8 prior to version 4.8 SP2 HF1 are affected by an injection vulnerability. This vulnerability is fixed in NetIQ IdM 4.8 SP2 HF1.
Affected Software
5 affected components
Microfocus Identity Manager=4.8
Microfocus Identity Manager=4.8-hf1
Microfocus Identity Manager=4.8-sp1
Microfocus Identity Manager=4.8-sp1_hf1
Microfocus Identity Manager=4.8-sp2
Event History
Nov 20, 2020
CVE Published
via MITRE·03:24 PM
Data Sourced
via MITRE·03:24 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-25839?
CVE-2020-25839 is categorized as an injection vulnerability, which can lead to unauthorized access or manipulation of data.
2
How do I fix CVE-2020-25839?
To fix CVE-2020-25839, upgrade to NetIQ Identity Manager 4.8 SP2 HF1 or a later version.
3
What versions of NetIQ Identity Manager are affected by CVE-2020-25839?
CVE-2020-25839 affects NetIQ Identity Manager versions 4.8, 4.8 SP1, and 4.8 SP1 HF1.
4
Can CVE-2020-25839 impact my organization's security?
Yes, CVE-2020-25839 can impact organizational security by allowing attackers to exploit the injection vulnerability.
5
Is there a workaround for CVE-2020-25839 if I cannot upgrade?
There is no official workaround for CVE-2020-25839; upgrading is the recommended solution.