Fix for NetIQ shell code upload
Vulnerability Description
The certificate upload in NetIQ eDirectory PKI plugin before 8.8.8 Patch 10 Hotfix 1 could be abused to upload JSP code which could be used by authenticated attackers to execute JSP applets on the iManager server.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-7429
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- SySS GmbH
References
More from NetIQ
View All →Affected Vendor
NetIQ
View all reports →