Vulnerabilities
Vulnerable Software
Novell ZENworks Configuration Management before 11.2.4 allows XSS.
CVSS Score
6.1
EPSS Score
0.002
Published
2020-01-25
Novell ZENworks Configuration Management before 11.2.4 allows obtaining sensitive trace information.
CVSS Score
7.5
EPSS Score
0.005
Published
2020-01-25
SQL injection vulnerability in the GetReRequestData method of the GetStoredResult class in Novell ZENworks Configuration Management (ZCM) allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVSS Score
9.8
EPSS Score
0.013
Published
2017-08-09
Directory traversal vulnerability in the doPost method of the Rtrlet class in Novell ZENworks Configuration Management (ZCM) allows remote attackers to upload and execute arbitrary files via unspecified vectors.
CVSS Score
9.8
EPSS Score
0.056
Published
2017-08-09
SQL injection vulnerability in the ScheduleQuery method of the schedule class in Novell ZENworks Configuration Management (ZCM) allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVSS Score
9.8
EPSS Score
0.015
Published
2017-08-09
The FileViewer class in Novell ZENworks Configuration Management (ZCM) allows remote authenticated users to read arbitrary files via the filename variable.
CVSS Score
6.5
EPSS Score
0.004
Published
2017-08-09
Rtrlet.class in Novell ZENworks Configuration Management (ZCM) allows remote attackers to obtain Session IDs of logged in users via a value of ShowLogins for the maintenance variable.
CVSS Score
7.5
EPSS Score
0.012
Published
2017-08-09
com.novell.zenworks.inventory.rtr.actionclasses.wcreports in Novell ZENworks Configuration Management (ZCM) allows remote attackers to read arbitrary folders via the dirname variable.
CVSS Score
7.5
EPSS Score
0.007
Published
2017-08-09
Stack-based buffer overflow in the logging functionality in the Preboot Policy service in Novell ZENworks Configuration Management (ZCM) allows remote attackers to execute arbitrary code via unspecified vectors.
CVSS Score
9.8
EPSS Score
0.128
Published
2017-08-09
The ChangePassword RPC method in Novell ZENworks Configuration Management (ZCM) 11.3 and 11.4 allows remote attackers to conduct XPath injection attacks, and read arbitrary text files, via a malformed query involving a system entity reference.
CVSS Score
5.3
EPSS Score
0.005
Published
2016-02-18


Contact Us

Shodan ® - All rights reserved