CVE-2024-3969: XML External Entity injection vulnerability in iManager
Published May 28, 2024
·Updated
XML External Entity injection vulnerability found in OpenText™ iManager 3.2.6.0200. This could lead to remote code execution by parsing untrusted XML payload
Affected Software
6 affected components
MicroFocus Imanager>=3.0<3.2.6
MicroFocus Imanager=3.2.6
MicroFocus Imanager=3.2.6-patch1
MicroFocus Imanager=3.2.6-patch2
MicroFocus Imanager=3.2.6-patch3
OpenText iManager
Event History
May 28, 2024
CVE Published
via MITRE·02:38 PM
Data Sourced
via MITRE·02:38 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-3969?
CVE-2024-3969 is considered a high severity vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2024-3969?
To fix CVE-2024-3969, update OpenText iManager to version 3.2.6-patch3 or later.
3
What systems are affected by CVE-2024-3969?
CVE-2024-3969 affects OpenText iManager versions 3.0 up to 3.2.6 and its patches.
4
What type of vulnerability is CVE-2024-3969?
CVE-2024-3969 is an XML External Entity (XXE) injection vulnerability.
5
Can CVE-2024-3969 be exploited remotely?
Yes, CVE-2024-3969 can be exploited remotely by sending untrusted XML payloads.