VulnerabilityModified
CVE-2014-3460
Directory traversal vulnerability in the DumpToFile method in the NQMcsVarSet ActiveX control in Agent Manager in NetIQ Sentinel allows remote attackers to create arbitrary files, and consequently execute arbitrary code, via a crafted pathname.
MEDIUM 6.8EPSS 3.27%
Does this matter?
Lower severity and a low EPSS score (3.27%). Track it; it rarely justifies an emergency change on its own.
Description
Directory traversal vulnerability in the DumpToFile method in the NQMcsVarSet ActiveX control in Agent Manager in NetIQ Sentinel allows remote attackers to create arbitrary files, and consequently execute arbitrary code, via a crafted pathname.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 3.27% probability · 88th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- microfocus/sentinel · microfocus/sentinel agent manager
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/58635
- http://www.novell.com/support/kb/doc.php?id=7015183
- http://www.securityfocus.com/bid/67487
- http://www.securitytracker.com/id/1030434
- http://zerodayinitiative.com/advisories/ZDI-14-134/
- http://secunia.com/advisories/58635
- http://www.novell.com/support/kb/doc.php?id=7015183
- http://www.securityfocus.com/bid/67487
- http://www.securitytracker.com/id/1030434
- http://zerodayinitiative.com/advisories/ZDI-14-134/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.