PT-2015-3478 · Novell · Novell Zenworks Configuration Management
Published
2015-06-07
·
Updated
2015-06-08
·
CVE-2010-5323
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Novell ZENworks Configuration Management (ZCM) versions prior to 10.3
Description
A directory traversal issue exists in the UploadServlet component of the Remote Management feature. This allows remote attackers to execute arbitrary code by providing a crafted WAR pathname in the
filename parameter, in conjunction with WAR content in the POST data.Recommendations
For versions prior to 10.3, update to version 10.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the UploadServlet component to minimize the risk of exploitation. Avoid using the
filename parameter in the affected UploadServlet until the issue is resolved.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Novell Zenworks Configuration Management