PT-2015-3478 · Novell · Novell Zenworks Configuration Management
Publicado
2015-06-07
·
Atualizado
2015-06-08
·
CVE-2010-5323
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Novell ZENworks Configuration Management (ZCM) versions prior to 10.3
Description
A directory traversal issue exists in the UploadServlet component of the Remote Management feature. This allows remote attackers to execute arbitrary code by providing a crafted WAR pathname in the
filename parameter, in conjunction with WAR content in the POST data.Recommendations
For versions prior to 10.3, update to version 10.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the UploadServlet component to minimize the risk of exploitation. Avoid using the
filename parameter in the affected UploadServlet until the issue is resolved.Exploit
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Novell Zenworks Configuration Management