Description
Remote Code Execution has been discovered in OpenText™ iManager 3.2.6.0200. The vulnerability can trigger remote code execution unisng unsafe java object deserialization.
Problem types
CWE-502 Deserialization of Untrusted Data
Product status
3.0.0 (rpm, exe)
Credits
Blaine Herro (Yahoo! Inc. VRT)
References
www.netiq.com/...ta/imanager326_patch3_hf1_releasenotes.html
www.netiq.com/...ta/imanager326_patch3_hf1_releasenotes.html