CVE-2024-3486: XML External Entity injection vulnerability in iManager
Published May 15, 2024
·Updated
XML External Entity injection vulnerability found in OpenText™ iManager 3.2.6.0200. This could lead to information disclosure and remote code execution.
Affected Software
6 affected components
MicroFocus Imanager>=3.0<3.2.6
MicroFocus Imanager=3.2.6
MicroFocus Imanager=3.2.6-patch1
MicroFocus Imanager=3.2.6-patch2
MicroFocus Imanager=3.2.6-patch3
OpenText iManager
Event History
May 15, 2024
CVE Published
via MITRE·04:46 PM
Data Sourced
via MITRE·04:46 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-3486?
CVE-2024-3486 is classified as a high severity vulnerability due to its potential for information disclosure and remote code execution.
2
How do I fix CVE-2024-3486?
To fix CVE-2024-3486, upgrade OpenText iManager to version 3.2.6.0201 or later.
3
What type of vulnerability is CVE-2024-3486?
CVE-2024-3486 is an XML External Entity (XXE) injection vulnerability.
4
What software is affected by CVE-2024-3486?
CVE-2024-3486 affects OpenText iManager versions up to 3.2.6.0200.
5
Can CVE-2024-3486 lead to remote code execution?
Yes, exploiting CVE-2024-3486 can lead to remote code execution and information disclosure.