Loading
NetIQ Identity Manager before 4.5.6.1 allowed uploading files with double extensions or non-image content in the Themes handling of the User Application Administration, allowing malicious user administrators to potentially execute code or mislead users.
Use CWE-434, Netiq vendor hub and Identity Manager product page to widen CVE-2017-9279 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2017-7427, CVE-2018-1348 and CVE-2018-7673 for nearby disclosures in the same product family.