The certificate upload in NetIQ eDirectory PKI plugin...
High severity
Unreviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
Mar 2, 2018
Published to the GitHub Advisory Database
May 13, 2022
Last updated
Feb 1, 2023
The certificate upload in NetIQ eDirectory PKI plugin before 8.8.8 Patch 10 Hotfix 1 could be abused to upload JSP code which could be used by authenticated attackers to execute JSP applets on the iManager server.
References