CVE-2024-4429: Cross Site Request Forgery vulnerability in iManager
Published May 28, 2024
·Updated
Cross-Site Request Forgery vulnerability has been discovered in OpenText™ iManager 3.2.6.0200. This could lead to sensitive information disclosure.
Affected Software
7 affected components
MicroFocus Imanager>=3.0<3.2.6
MicroFocus Imanager=3.2.6
MicroFocus Imanager=3.2.6-patch1
MicroFocus Imanager=3.2.6-patch2
MicroFocus Imanager=3.2.6-patch3
MicroFocus Imanager=3.2.6-patch3_hotfix1
OpenText iManager
Event History
May 28, 2024
CVE Published
via MITRE·02:38 PM
Data Sourced
via MITRE·02:38 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-4429?
CVE-2024-4429 is classified as a Cross-Site Request Forgery vulnerability that can lead to sensitive information disclosure.
2
How do I fix CVE-2024-4429?
To address CVE-2024-4429, apply the latest patches released for OpenText™ iManager 3.2.6 or higher.
3
Which versions of OpenText™ iManager are affected by CVE-2024-4429?
CVE-2024-4429 affects OpenText™ iManager versions 3.2.6 and prior, including all patches and variants.
4
What type of attack is associated with CVE-2024-4429?
CVE-2024-4429 is associated with Cross-Site Request Forgery attacks that exploit user sessions.
5
Can CVE-2024-4429 lead to data breaches?
Yes, CVE-2024-4429 can potentially lead to data breaches by allowing unauthorized actions that disclose sensitive information.