The certificate upload in NetIQ eDirectory PKI plugin before 8.8.8 Patch 10 Hotfix 1 could be abused to upload JSP code which could be used by authenticated attackers to execute JSP applets on the iManager server.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
The product does not validate, or incorrectly validates, a certificate.