CVE-2024-3970: Server-Side Request Forgery vulnerability in iManager
Server Side Request Forgery vulnerability has been discovered in OpenText™ iManager 3.2.6.0200. This could lead to senstive information disclosure by directory traversal.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3970?
CVE-2024-3970 has been classified as a Server Side Request Forgery vulnerability which could lead to sensitive information disclosure.
How do I fix CVE-2024-3970?
To fix CVE-2024-3970, users should update to the latest version or patch of OpenText iManager as recommended by the vendor.
What versions of OpenText iManager are affected by CVE-2024-3970?
CVE-2024-3970 affects OpenText iManager versions up to and including 3.2.6 and its patch versions.
What type of attack does CVE-2024-3970 enable?
CVE-2024-3970 enables Server Side Request Forgery attacks which may lead to unauthorized access to sensitive information.
Is there a workaround for CVE-2024-3970?
Currently, applying the recommended patches or updates is the only effective mitigation for CVE-2024-3970.