CVE-2011-2654
Novell Cloud Manager Insufficient Framework User Validation Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The RPC implementation in the server in Novell Cloud Manager 1.1.2 before Patch 3 does not properly initialize objects, which allows remote attackers to execute arbitrary code by making RPC calls that leverage incorrect privileges associated with a partially initialized session.
La implementación de RPC en el servidor de Novell Cloud Manager v1.1.2 anterior a la revisión 3 no inicializa correctamente los objetos, que permite a atacantes remotos ejecutar código arbitrario mediante llamadas RPC que aprovechan los privilegios incorrectos asociados con una sesión parcialmente inicializado.
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Novell Cloud Manager. Authentication is not required to exploit this vulnerability.
The specific flaw exists within how the application implements an RPC method. Due to incompletely initializing an object, the application will store a partially initialized session. This partially initialized session will allow one to make privileged RPC calls to the server. This can lead to code execution under the context of the service.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2011-07-06 CVE Reserved
- 2011-09-02 CVE Published
- 2024-08-06 CVE Updated
- 2024-09-22 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://download.novell.com/Download?buildid=NSONlV5PqMo~ | X_refsource_confirm | |
http://www.securityfocus.com/bid/49432 | Vdb Entry | |
http://www.securitytracker.com/id?1026006 | Vdb Entry | |
http://zerodayinitiative.com/advisories/ZDI-11-278 | X_refsource_misc |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/45845 | 2011-10-06 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Novell Search vendor "Novell" | Cloud Manager Search vendor "Novell" for product "Cloud Manager" | <= 1.1.2 Search vendor "Novell" for product "Cloud Manager" and version " <= 1.1.2" | patch2 |
Affected
| ||||||
Novell Search vendor "Novell" | Cloud Manager Search vendor "Novell" for product "Cloud Manager" | 1.1.2 Search vendor "Novell" for product "Cloud Manager" and version "1.1.2" | - |
Affected
| ||||||
Novell Search vendor "Novell" | Cloud Manager Search vendor "Novell" for product "Cloud Manager" | 1.1.2 Search vendor "Novell" for product "Cloud Manager" and version "1.1.2" | patch1 |
Affected
|