← back
CVE-2017-9279lowCWE-434

NetIQ Identity Manager allowed uploading of user icons with incorrect types or extensions

8Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 2epss 0.9%
exploitation probability
0.9%top 44% of all CVEs
observed exploitation
nono source reports it
NetIQ Identity Manager before 4.5.6.1 allowed uploading files with double extensions or non-image content in the Themes handling of the User Application Administration, allowing malicious user administrators to potentially execute code or mislead users.
CVSS:3.0/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N
Affected products
NetIQ · Identity Manager