CVE-2013-1084
Novell ZENworks umaninv Information Disclosure Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Directory traversal vulnerability in the GetFle method in the umaninv service in Novell ZENworks Configuration Management (ZCM) 11.2.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the Filename parameter in a GetFile action to zenworks-unmaninv/.
Vulnerabilidad de salto de directorio en el método GetFle del servicio umaninv de Novell ZENworks Configuration Management (ZCM) 11.2.3 que permite a atacantes remotos leer archivos de su elección a través de .. (punto punto) en el parámetro Filename en una acción GetFile en zenworks-unmaninv /.
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Novell ZENworks. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the unmaninv web service. The issue lies in the failure to user-supplied sanitize input when returning the contents of a file. An attacker can leverage this vulnerability to retrieve credentials which can then be leveraged to execute code under the context of SYSTEM.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2013-01-11 CVE Reserved
- 2013-11-02 CVE Published
- 2024-09-17 CVE Updated
- 2024-09-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.novell.com/support/kb/doc.php?id=7012027 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/55450 | 2013-11-21 | |
http://www.novell.com/support/kb/doc.php?id=7012760 | 2013-11-21 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Novell Search vendor "Novell" | Zenworks Configuration Management Search vendor "Novell" for product "Zenworks Configuration Management" | 11.2.3 Search vendor "Novell" for product "Zenworks Configuration Management" and version "11.2.3" | - |
Affected
|