📦 Imanager

by Microfocus

🔍 What is Imanager?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2021-38135

HIGH CVSS 8.6 Nov 22, 2024

CVE-2021-38135 is an External Service Interaction vulnerability in OpenText iManager that allows attackers to force the application to interact with arbitrary external services. This could lead to ser...

CVE-2023-24466

HIGH CVSS 7.5 Nov 22, 2024

CVE-2023-24466 is an XML External Entity (XXE) injection vulnerability in OpenText iManager's GET parameter processing. Attackers can exploit this to read arbitrary files from the server, potentially ...

CVE-2021-38116

HIGH CVSS 8.8 Nov 22, 2024

CVE-2021-38116 is an elevation of privilege vulnerability in OpenText iManager that allows authenticated users to execute arbitrary commands with higher privileges. This affects all iManager versions ...

CVE-2020-11859

HIGH CVSS 7.6 Nov 6, 2024

CVE-2020-11859 is an improper input validation vulnerability in OpenText iManager that allows cross-site scripting (XSS) attacks. Attackers can inject malicious scripts into web pages viewed by other ...

CVE-2024-3969

HIGH CVSS 7.8 May 28, 2024

This XML External Entity (XXE) injection vulnerability in OpenText iManager 3.2.6.0200 allows attackers to execute remote code by submitting malicious XML payloads. It affects systems running this spe...

CVE-2024-3968

HIGH CVSS 7.8 May 15, 2024

This vulnerability allows remote attackers to execute arbitrary code on OpenText iManager 3.2.6.0200 systems by exploiting a custom file upload task. The flaw stems from improper input validation (CWE...

CVE-2024-3486

HIGH CVSS 7.8 May 15, 2024

This CVE describes an XML External Entity (XXE) injection vulnerability in OpenText iManager 3.2.6.0200. Attackers can exploit this vulnerability to read sensitive files from the server or potentially...

CVE-2021-38134

MEDIUM CVSS 6.1 Nov 22, 2024

CVE-2021-38134 is a cross-site scripting (XSS) vulnerability in OpenText iManager's URL for access component. Attackers can inject malicious scripts that execute in users' browsers when they visit cra...

CVE-2021-38118

MEDIUM CVSS 5.5 Nov 22, 2024

CVE-2021-38118 is an improper input validation vulnerability in OpenText iManager that could allow attackers to manipulate application behavior through crafted inputs. This affects organizations using...

CVE-2024-3488

MEDIUM CVSS 5.6 May 15, 2024

This CVE describes an unauthenticated file upload vulnerability in OpenText iManager 3.2.6.0200. Attackers can upload arbitrary files without authentication, potentially leading to remote code executi...

CVE-2024-3484

MEDIUM CVSS 5.7 May 15, 2024

This path traversal vulnerability in OpenText iManager 3.2.6.0200 allows attackers to access files outside the intended directory. It can lead to privilege escalation or sensitive file disclosure. Org...