// For flags

CVE-2011-2654

Novell Cloud Manager Insufficient Framework User Validation Vulnerability

Severity Score

9.3
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The RPC implementation in the server in Novell Cloud Manager 1.1.2 before Patch 3 does not properly initialize objects, which allows remote attackers to execute arbitrary code by making RPC calls that leverage incorrect privileges associated with a partially initialized session.

La implementación de RPC en el servidor de Novell Cloud Manager v1.1.2 anterior a la revisión 3 no inicializa correctamente los objetos, que permite a atacantes remotos ejecutar código arbitrario mediante llamadas RPC que aprovechan los privilegios incorrectos asociados con una sesión parcialmente inicializado.

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Novell Cloud Manager. Authentication is not required to exploit this vulnerability.
The specific flaw exists within how the application implements an RPC method. Due to incompletely initializing an object, the application will store a partially initialized session. This partially initialized session will allow one to make privileged RPC calls to the server. This can lead to code execution under the context of the service.

*Credits: 1c239c43f521145fa8385d64a9c32243
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2011-07-06 CVE Reserved
  • 2011-09-02 CVE Published
  • 2024-08-06 CVE Updated
  • 2024-09-22 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-20: Improper Input Validation
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Novell
Search vendor "Novell"
Cloud Manager
Search vendor "Novell" for product "Cloud Manager"
<= 1.1.2
Search vendor "Novell" for product "Cloud Manager" and version " <= 1.1.2"
patch2
Affected
Novell
Search vendor "Novell"
Cloud Manager
Search vendor "Novell" for product "Cloud Manager"
1.1.2
Search vendor "Novell" for product "Cloud Manager" and version "1.1.2"
-
Affected
Novell
Search vendor "Novell"
Cloud Manager
Search vendor "Novell" for product "Cloud Manager"
1.1.2
Search vendor "Novell" for product "Cloud Manager" and version "1.1.2"
patch1
Affected