CVE-2024-3487: Broken Authentication vulnerability in iManager
Published May 15, 2024
·Updated
Broken Authentication vulnerability discovered in OpenText™ iManager 3.2.6.0200. This vulnerability allows an attacker to manipulate certain parameters to bypass authentication.
Affected Software
6 affected components
MicroFocus Imanager>=3.0<3.2.6
MicroFocus Imanager=3.2.6
MicroFocus Imanager=3.2.6-patch1
MicroFocus Imanager=3.2.6-patch2
MicroFocus Imanager=3.2.6-patch3
OpenText iManager
Event History
May 15, 2024
CVE Published
via MITRE·04:47 PM
Data Sourced
via MITRE·04:47 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-3487?
CVE-2024-3487 is classified as a Broken Authentication vulnerability that poses significant security risks.
2
How do I fix CVE-2024-3487?
To address CVE-2024-3487, it is recommended to apply the latest security patches and updates provided by OpenText for iManager.
3
What products are impacted by CVE-2024-3487?
CVE-2024-3487 affects OpenText iManager version 3.2.6.0200 and certain previous versions.
4
Can CVE-2024-3487 be exploited remotely?
Yes, CVE-2024-3487 can be exploited remotely by manipulating parameters to bypass authentication.
5
What are the potential consequences of CVE-2024-3487?
The exploitation of CVE-2024-3487 can lead to unauthorized access to sensitive information and systems.