CVE-2018-7679
UnknownEPSS 2.31%
Last modified
CVE-2018-7679 is a vulnerability of currently unknown severity. Micro Focus Solutions Business Manager versions prior to 11.4 when ASP.NET is configured with execute permission on the virtual directories and does not validate the contents of user avatar images, could lead to remote code execution.. EPSS estimates a 2.31% chance of exploitation in the next 30 days.
Description
Micro Focus Solutions Business Manager versions prior to 11.4 when ASP.NET is configured with execute permission on the virtual directories and does not validate the contents of user avatar images, could lead to remote code execution.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Microfocus | Solutions Business Manager | < 11.4 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-7679?
Micro Focus Solutions Business Manager versions prior to 11.4 when ASP.NET is configured with execute permission on the virtual directories and does not validate the contents of user avatar images, could lead to remote code execution.
How severe is CVE-2018-7679?
Severity scoring for CVE-2018-7679 is pending analysis. The EPSS model estimates a 2.31% probability of exploitation in the next 30 days.
How do I fix CVE-2018-7679?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-7673The NetIQ Identity Manager communication channel, in version…5.1
- CVE-2018-7674The NetIQ Identity Manager user console, in versions prior t…2.1
- CVE-2018-7675In NetIQ Sentinel before 8.1.x, a Sentinel user is logged in…2.8
- CVE-2018-7676The NetIQ Identity Manager, in versions prior to 4.7, userap…3.9
- CVE-2018-7677A CSRF exposure exists in NetIQ Access Manager (NAM) 4.4 Ide…3.5
- CVE-2018-7678A cross site scripting vulnerability exist in the Administra…3.5
- CVE-2018-7680Micro Focus Solutions Business Manager versions prior to 11.…
- CVE-2018-7681Micro Focus Solutions Business Manager versions prior to 11.…
- CVE-2018-7682Micro Focus Solutions Business Manager versions prior to 11.…
- CVE-2018-7683Micro Focus Solutions Business Manager versions prior to 11.…
- CVE-2018-7685The decoupled download and installation steps in libzypp bef…7.8
- CVE-2018-7686Information leakage vulnerability in NetIQ eDirectory before…
Are you affected by CVE-2018-7679?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
