CVE-2019-3489 Vulnerability Details

  /     /     /  

CVE-2019-3489 Metadata Quick Info

CVE Published: 01/04/2019 | CVE Updated: 04/08/2024 | CVE Year: 2019
Source: microfocus | Vendor: Micro Focus | Product: Micro Focus Content Manager
Status : PUBLISHED

CVE-2019-3489 Description

An unauthenticated file upload vulnerability has been identified in the Web Client component of Micro Focus Content Manager 9.1, 9.2, and 9.3 when configured to use the ADFS authentication method. The vulnerability could be exploited by an unauthenticated remote attacker to upload content to arbitrary locations on the Content Manager server.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: Remote upload content to arbitrary locations
Source: Micro Focus

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).