CVE-2024-3967: Remote Code Execution vulnerability in the iManager
Published May 15, 2024
·Updated
Remote Code Execution has been discovered in OpenText™ iManager 3.2.6.0200. The vulnerability can trigger remote code execution unisng unsafe java object deserialization.
Affected Software
6 affected components
MicroFocus Imanager>=3.0<3.2.6
MicroFocus Imanager=3.2.6
MicroFocus Imanager=3.2.6-patch1
MicroFocus Imanager=3.2.6-patch2
MicroFocus Imanager=3.2.6-patch3
OpenText iManager
Event History
May 15, 2024
CVE Published
via MITRE·04:40 PM
Data Sourced
via MITRE·04:40 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-3967?
CVE-2024-3967 is categorized as a critical remote code execution vulnerability.
2
How do I fix CVE-2024-3967?
To remediate CVE-2024-3967, update OpenText iManager to the latest patched version.
3
What versions of OpenText iManager are affected by CVE-2024-3967?
CVE-2024-3967 affects OpenText iManager versions up to 3.2.6, including specific patches.
4
What type of vulnerability is CVE-2024-3967?
CVE-2024-3967 is a remote code execution vulnerability due to unsafe Java object deserialization.
5
Can CVE-2024-3967 be exploited remotely?
Yes, CVE-2024-3967 can be exploited remotely, allowing attackers to execute arbitrary code on the server.