CVE-2024-3488: File Upload vulnerability in unauthenticated session found in iManager.
Published May 15, 2024
·Updated
File Upload vulnerability in unauthenticated session found in OpenText™ iManager 3.2.6.0200. The vulnerability could allow ant attacker to upload a file without authentication.
Affected Software
6 affected components
MicroFocus Imanager>=3.0<3.2.6
MicroFocus Imanager=3.2.6
MicroFocus Imanager=3.2.6-patch1
MicroFocus Imanager=3.2.6-patch2
MicroFocus Imanager=3.2.6-patch3
OpenText iManager
Event History
May 15, 2024
CVE Published
via MITRE·04:47 PM
Data Sourced
via MITRE·04:47 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-3488?
CVE-2024-3488 is classified as a critical vulnerability due to its potential for unauthenticated file uploads.
2
How do I fix CVE-2024-3488?
To fix CVE-2024-3488, it is recommended to upgrade to the latest patched version of OpenText™ iManager.
3
What software is affected by CVE-2024-3488?
CVE-2024-3488 affects OpenText™ iManager versions 3.2.6 and prior, including various patches.
4
What is the potential impact of CVE-2024-3488?
The potential impact of CVE-2024-3488 includes unauthorized file uploads which can lead to system compromise.
5
Is authentication required to exploit CVE-2024-3488?
No, CVE-2024-3488 allows file uploads without any authentication, making it particularly dangerous.