CVE-2020-11852

DKIM key management page vulnerability on Micro Focus Secure Messaging Gateway (SMG). Affecting all SMG Appliance running releases prior to July 2020. The vulnerability could allow a logged in user with rights to generate DKIM key information to inject system commands into the call to the DKIM system command.
Configurations

Configuration 1 (hide)

cpe:2.3:a:microfocus:secure_messaging_gateway:*:*:*:*:*:*:*:*

History

21 Nov 2024, 04:58

Type Values Removed Values Added
References () https://support.microfocus.com/kb/doc.php?id=7024775 - () https://support.microfocus.com/kb/doc.php?id=7024775 -

07 Nov 2023, 03:15

Type Values Removed Values Added
References (MISC) https://support.microfocus.com/kb/doc.php?id=7024775 - Vendor Advisory () https://support.microfocus.com/kb/doc.php?id=7024775 -

Information

Published : 2020-08-07 16:15

Updated : 2024-11-21 04:58


NVD link : CVE-2020-11852

Mitre link : CVE-2020-11852

CVE.ORG link : CVE-2020-11852


JSON object : View

Products Affected

microfocus

  • secure_messaging_gateway
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')