RULE(RULE ID:334072)

Rule General Information
Release Date: 2021-11-10
Rule Name: Micro Focus Secure Messaging Gateway Command Injection Vulnerability (CVE-2020-11852)
Severity:
CVE ID:
Rule Protection Details
Description: DKIM key management page vulnerability on Micro Focus Secure Messaging Gateway (SMG). Affecting all SMG Appliance running releases prior to July 2020. The vulnerability could allow a logged in user with rights to generate DKIM key information to inject system commands into the call to the DKIM system command.
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, Others
Reference: https://support.microfocus.com/kb/doc.php?id=7024775
Solutions
The vendor has released upgrade patches to fix vulnerabilities, please visit:
https://support.microfocus.com/kb/doc.php?id=7024775