CVE-2012-5930
Last modified
CVE-2012-5930 is a vulnerability of currently unknown severity. The pa_modify_accounts function in auth.dll in unifid.exe in NetIQ Privileged User Manager 2.3.x before 2.3.1 HF2 does not require authentication for the modifyAccounts method, which allows remote attackers to change the passwords of administrative accounts via a crafted application/x-amf request.. EPSS estimates a 7.37% chance of exploitation in the next 30 days.
Description
The pa_modify_accounts function in auth.dll in unifid.exe in NetIQ Privileged User Manager 2.3.x before 2.3.1 HF2 does not require authentication for the modifyAccounts method, which allows remote attackers to change the passwords of administrative accounts via a crafted application/x-amf request.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Microfocus | Privileged User Manager | 2.3.0 |
| Microfocus | Privileged User Manager | 2.3.1 |
References
- https://www.netiq.com/support/kb/doc.php?id=7011385Vendor Advisory
- https://www.netiq.com/support/kb/doc.php?id=7011385Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-5930?
How severe is CVE-2012-5930?
How do I fix CVE-2012-5930?
Are you affected by CVE-2012-5930?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
