CVE-2012-5932 is an eval injection vulnerability in NetIQ Privileged User Manager 2.3.x before 2.3.1 HF2, specifically within the ldapagnt_eval function of ldapagnt.dll in unifid.exe. This critical vulnerability, with a CVSS score of 10.0, allows unauthenticated remote attackers to execute arbitrary Perl code by sending a crafted application/x-amf request. While not listed in CISA's KEV catalog, a Metasploit module and ExploitDB entry confirm the existence of public exploit code, indicating a high potential for exploitation despite a lack of observed active exploitation or community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.3.0CPE matchmatch criteria | cpe:2.3:a:microfocus:privileged_user_manager:2.3.0:*:*:*:*:*:*:* | ||
2.3.1CPE matchmatch criteria | cpe:2.3:a:microfocus:privileged_user_manager:2.3.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.