Vulnerabilities

Yahoo Discloses NetIQ iManager Flaws Allowing Remote Code Execution

Yahoo researchers found nearly a dozen vulnerabilities in OpenText’s NetIQ iManager and some could have been chained for unauthenticated RCE.

Yahoo researchers found nearly a dozen vulnerabilities in OpenText’s NetIQ iManager and some could have been chained for unauthenticated RCE.

Yahoo’s Paranoid vulnerability research team has identified nearly a dozen flaws in OpenText’s NetIQ iManager product, including some that could have been chained for unauthenticated remote code execution.

NetIQ iManager is an enterprise directory management tool that enables secure remote access to network administration utilities and content.

The Paranoid team discovered 11 vulnerabilities that could have been exploited individually for cross-site request forgery (CSRF), server-side request forgery (SSRF), remote code execution (RCE), arbitrary file upload, authentication bypass, file disclosure, and privilege escalation. 

Patches for these vulnerabilities were released with updates rolled out in April, and Yahoo has now disclosed the details of some of the security holes, and explained how they could be chained.

Of the 11 vulnerabilities they found, Paranoid researchers described four in detail: CVE-2024-3487, an authentication bypass flaw, CVE-2024-3483, a command injection flaw, CVE-2024-3488, an arbitrary file upload flaw, and CVE-2024-4429, a CSRF validation bypass flaw.

Chaining these vulnerabilities could have allowed an attacker to compromise iManager remotely from the internet by getting a user connected to their corporate network to access a malicious website. 

Advertisement. Scroll to continue reading.

In addition to compromising an iManager instance, the researchers showed how an attacker could have obtained an administrator’s credentials and abused them to perform actions on their behalf. 

“Why does iManager end up being such a good target for attackers? iManager, like many other enterprise administrative consoles, sits in a highly privileged position, administering  downstream directory services,” explained Blaine Herro, a member of the Paranoids team and Yahoo’s Red Team. 

“These directory services maintain user account information, such as usernames, passwords, attributes, and group memberships. An attacker with this level of control over user accounts can fool downstream applications that rely on it as a source of truth,” Herro added. 

Related: WhiteRabbitNeo: High-Powered Potential of Uncensored AI Pentesting for Attackers and Defenders

Related: Google Patches Critical Chrome Vulnerability Reported by Apple

Related: Synology, QNAP, TrueNAS Address Vulnerabilities Exploited at Pwn2Own Ireland

Related Content

Endpoint Security

Microsoft fixed critical vulnerabilities across Azure, Entra, and SharePoint, while Apple patched a high-severity authentication bypass.

Vulnerabilities

The browser refresh eliminates over two dozen memory safety bugs, including critical use-after-free flaws.

Artificial Intelligence

Zenity researchers reported the findings to Anthropic and OpenAI in late 2025 and early 2026, but they remain unpatched.

Artificial Intelligence

An attacker could self-register, sign in for board-level API access, and import a new company for code execution.

Vulnerabilities

Patches were rolled out for two dozen vulnerabilities, including one with public proof-of-concept (PoC) code.

Vulnerabilities

Tracked as CVE-2026-63077, the critical bug can be exploited without authentication for remote code execution.

Mobile & Wireless

The chain involved the exploitation of several vulnerabilities in the Samsung Members and Samsung Account applications.

Vulnerabilities

The flaws can be exploited for remote code execution, authentication bypass, and EncryptInterceptor bypass.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version