CVE-2017-9279: Netiq Identity Manager
High severity, CVSS 7.2. EPSS: 0.9% chance of exploitation in the next 30 days.
NetIQ Identity Manager before 4.5.6.1 allowed uploading files with double extensions or non-image content in the Themes handling of the User Application Administration, allowing malicious user administrators to potentially execute code or mislead users.
Affected products
- Netiq Identity Manager: before 4.5.6.1 (fixed in 4.5.6.1)
Published 2018-03-02. Last modified 2026-06-17.