Imanager
Vendor:
First CVE: Dec 12, 2018 · Active for 7 years
22
Total CVEs
More Total CVEs than 94% of tracked products
11.0
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
8.4
Avg CVSS
Higher Avg CVSS than 75% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Imanager over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 12, 2018
7 years ago
Most Recent CVE
Nov 22, 2024
609 days ago
CVE Severity & Scoring
Imanager22 CVEs
23%
23%
55%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (4.5%)
Network21 (95.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low22 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None16 (72.7%)
Unknown0 (0.0%)
Required6 (27.3%)
Privileges Required
Low4 (18.2%)
High0 (0.0%)
None18 (81.8%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-38117CRITICAL Possible Command injection Vulnerability
in iManager has been discovered in
OpenText™ iManager 3.2.4.0000. | Nov 22, 2024 | 9.8 | 30 | NO | NO |
CVE-2024-3969CRITICAL XML External Entity injection vulnerability found in OpenText™ iManager 3.2.6.0200. This could lead to remote code execution by parsing untrusted XML payload
| May 28, 2024 | 9.8 | 30 | NO | NO |
CVE-2024-3968CRITICAL Remote Code
Execution has been discovered in
OpenText™ iManager 3.2.6.0200. The vulnerability can
trigger remote code execution using custom file upload task. | May 15, 2024 | 9.8 | 28 | NO | NO |
CVE-2023-24467CRITICAL Possible Command Injection
in iManager GET parameter has been discovered in
OpenText™ iManager 3.2.6.0000. | Nov 22, 2024 | 9.8 | 27 | NO | NO |
CVE-2021-38135CRITICAL Possible
External Service Interaction attack
in iManager has been discovered in
OpenText™ iManager 3.2.6.0000. | Nov 22, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-3967CRITICAL Remote Code
Execution has been discovered in
OpenText™ iManager 3.2.6.0200. The vulnerability can
trigger remote code execution unisng unsafe java object deserialization.
| May 15, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-3487CRITICAL Broken Authentication vulnerability discovered in OpenText™ iManager 3.2.6.0200. This
vulnerability allows an attacker to manipulate certain parameters to bypass
authentication.
| May 15, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-3486CRITICAL XML External Entity injection vulnerability found in OpenText™ iManager 3.2.6.0200. This could lead to information disclosure and remote code execution.
| May 15, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-3484CRITICAL Path Traversal found in OpenText™ iManager 3.2.6.0200. This can lead to privilege escalation
or file disclosure.
| May 15, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-3483CRITICAL Remote Code
Execution has been discovered in
OpenText™ iManager 3.2.6.0200. The vulnerability can
trigger command injection and insecure deserialization issues.
| May 15, 2024 | 9.8 | 27 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (22 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (22 CVEs).
Media Mentions
Signals from CVEs in this product scope (22 CVEs).
Top CNAs Publishing CVEs For Imanager
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.2.6 | 15 | 9.1 | 0.5% | 0 | 0 |