CVE Vulnerabilities

CVE-2014-4509

Published: Jun 21, 2014 | Modified: Sep 27, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The MKDQUOTESAFE function in the Fan-out driver scripts in Fan-Out Platform Services in Novell Identity Manager (aka IDM) 4.0.2 allows local users to execute arbitrary commands by leveraging eDirectory POSIX attribute changes to insert shell metacharacters.

Affected Software

Name Vendor Start Version End Version
Identity_manager Netiq 4.0.2 (including) 4.0.2 (including)

References