Skip to main content

Novell Access Manager Administration Console File Upload Vulnerability

Last Update Date: 28 Jan 2011 Release Date: 18 Jun 2010 4380 Views

RISK: Medium Risk

A vulnerability has been identified in Novell Access Manager, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by access and input validation errors in the "PortalModuleInstallManager" component within the Admin Console on Windows when handling uploaded files, which could allow remote unauthenticated attackers to upload malicious files to a vulnerable server via directory traversal attacks and execute arbitrary code with the privileges of the affected service.


Impact

  • Remote Code Execution

System / Technologies affected

  • Novell Access Manager version 3.1 SP1 (Support Pack 1) and prior

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

Upgrade to Access Manager version 3.1 Support Pack 2 (build 3.1.2-281 or later).


Vulnerability Identifier


Source


Related Link