CVE-2023-24466: Possible XML External Entity Injection in OpenText iManager
Published Nov 22, 2024
·Updated
Possible XML External Entity Injection
in iManager GET parameter has been discovered in OpenText™ iManager 3.2.6.0200.
Affected Software
5 affected components
OpenText iManager
MicroFocus Imanager>=3.0<3.2.6
MicroFocus Imanager=3.2.6
MicroFocus Imanager=3.2.6-patch1
MicroFocus Imanager=3.2.6-patch2
Event History
Nov 22, 2024
CVE Published
via MITRE·03:34 PM
Data Sourced
via MITRE·03:34 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-24466?
CVE-2023-24466 is classified as a high-severity vulnerability due to the potential for XML External Entity Injection.
2
How do I fix CVE-2023-24466?
To fix CVE-2023-24466, update OpenText iManager to the latest version that addresses this vulnerability.
3
What is the impact of CVE-2023-24466?
The impact of CVE-2023-24466 includes potential unauthorized data access and disclosure through XML External Entity Injection.
4
Who is affected by CVE-2023-24466?
CVE-2023-24466 affects users of OpenText iManager version 3.2.6.0200.
5
Is CVE-2023-24466 a common vulnerability pattern?
Yes, CVE-2023-24466 follows a common vulnerability pattern related to XML External Entity Injection, which is frequently found in web applications.