The certificate upload in NetIQ eDirectory PKI plugin before 8.8.8 Patch 10 Hotfix 1 could be abused to upload JSP code which could be used by authenticated attackers to execute JSP applets on the iManager server.
The product does not validate, or incorrectly validates, a certificate.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Edirectory | Microfocus | * | 8.8.8 (including) |
Edirectory | Netiq | 8.8.8-patch10 (including) | 8.8.8-patch10 (including) |
Edirectory | Netiq | 8.8.8-patch5 (including) | 8.8.8-patch5 (including) |
Edirectory | Netiq | 8.8.8-patch6 (including) | 8.8.8-patch6 (including) |
Edirectory | Netiq | 8.8.8-patch7 (including) | 8.8.8-patch7 (including) |
Edirectory | Netiq | 8.8.8-patch8 (including) | 8.8.8-patch8 (including) |
Edirectory | Netiq | 8.8.8-patch9 (including) | 8.8.8-patch9 (including) |