CVE-2024-3968: Remote Code Execution vulnerability in the iManager
Published May 15, 2024
·Updated
Remote Code Execution has been discovered in OpenText™ iManager 3.2.6.0200. The vulnerability can trigger remote code execution using custom file upload task.
Affected Software
6 affected components
MicroFocus Imanager>=3.0<3.2.6
MicroFocus Imanager=3.2.6
MicroFocus Imanager=3.2.6-patch1
MicroFocus Imanager=3.2.6-patch2
MicroFocus Imanager=3.2.6-patch3
OpenText iManager
Event History
May 15, 2024
CVE Published
via MITRE·04:39 PM
Data Sourced
via MITRE·04:39 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-3968?
CVE-2024-3968 has been classified with a high severity due to its potential for remote code execution.
2
How do I fix CVE-2024-3968?
To fix CVE-2024-3968, you should apply the latest patches for OpenText iManager, specifically patches 3.2.6-patch1, 3.2.6-patch2, or 3.2.6-patch3.
3
What software is affected by CVE-2024-3968?
CVE-2024-3968 affects OpenText iManager versions 3.2.6 and includes specific patches.
4
What impacts does CVE-2024-3968 have on my system?
CVE-2024-3968 allows an attacker to execute arbitrary code remotely, potentially compromising the entire system.
5
Is there a workaround for CVE-2024-3968 until a fix is applied?
Currently, there are no official workarounds for CVE-2024-3968, so it is critical to apply the appropriate patches as soon as possible.