PT-2013-6007 · Novell · Zenworks Configuration Management
Publicado
2013-11-02
·
Atualizado
2013-11-04
·
CVE-2013-6346
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Novell ZENworks Configuration Management (ZCM) versions prior to 11.2.4
Description
A cross-site request forgery (CSRF) issue exists in the ZCC page, allowing remote attackers to hijack the authentication of victims via unknown vectors.
Recommendations
For versions prior to 11.2.4, update to version 11.2.4 or later to resolve the issue.
Correção
CSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Zenworks Configuration Management