4.3

CVE-2012-6534

Exploit

Novell Sentinel Log Manager before 1.2.0.3 allows remote attackers to create data retention policies via a crafted text/x-gwt-rpc request to novelllogmanager/datastorageservice.rpc, and allows remote authenticated Report Administrators to create data retention policies via a search-results "Save Query As" "Save As Retention Policy" action.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NovellSentinel Log Manager Version <= 1.2.0.2
NovellSentinel Log Manager Version1.0.0.4
NovellSentinel Log Manager Version1.0.0.5
NovellSentinel Log Manager Version1.1.0.0
NovellSentinel Log Manager Version1.1.0.1
NovellSentinel Log Manager Version1.1.0.2
NovellSentinel Log Manager Version1.2
NovellSentinel Log Manager Version1.2.0.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 10.06% 0.928
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N