CVE-2024-3485: Server-Side Request Forgery vulnerability in iManager
Published May 15, 2024
·Updated
Server Side Request Forgery vulnerability has been discovered in OpenText™ iManager 3.2.6.0200. This could lead to senstive information disclosure.
Affected Software
6 affected components
MicroFocus Imanager>=3.0<3.2.6
MicroFocus Imanager=3.2.6
MicroFocus Imanager=3.2.6-patch1
MicroFocus Imanager=3.2.6-patch2
MicroFocus Imanager=3.2.6-patch3
OpenText iManager
Event History
May 15, 2024
CVE Published
via MITRE·04:45 PM
Data Sourced
via MITRE·04:45 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-3485?
CVE-2024-3485 has a high severity level due to its potential for sensitive information disclosure.
2
How do I fix CVE-2024-3485?
To fix CVE-2024-3485, it is recommended to update OpenText iManager to version 3.2.6.0201 or later.
3
What products are affected by CVE-2024-3485?
CVE-2024-3485 affects OpenText iManager versions up to 3.2.6 patch 3.
4
What type of vulnerability is CVE-2024-3485?
CVE-2024-3485 is a Server Side Request Forgery (SSRF) vulnerability.
5
Can CVE-2024-3485 lead to remote code execution?
CVE-2024-3485 does not lead to remote code execution but may allow sensitive information disclosure.