Summary
The host is running Novell NetIQ Privileged User Manager and is prone to remote code execution vulnerability.
Impact
Successful exploitation will allow attackers to execute perl code and change administrative credentials.
Impact Level: System/Application
Solution
Apply NetIQ Privileged User Manager 2.3.1 HF2 (2.3.1-2) or later, http://download.novell.com/protected/Summary.jsp?buildid=K6-PmbPjduA~
Insight
The flaws are due to an error in the 'ldapagnt' and 'auth' module due to not restricting access to certain methods, which can be exploited to execute perl code by passing arbitrary arguments to the Perl 'eval()' function via HTTP POST requests and attacker can change administrative credentials using the 'modifyAccounts()' function via HTTP POST requests.
Affected
Novell NetIQ Privileged User Manager 2.3.0 and 2.3.1
References
Severity
Classification
-
CVE CVE-2012-5930, CVE-2012-5931, CVE-2012-5932 -
CVSS Base Score: 10.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities