CVE-2012-6345
- EPSS 0.51%
- Veröffentlicht 25.01.2020 19:15:10
- Zuletzt bearbeitet 21.11.2024 01:46:02
Novell ZENworks Configuration Management before 11.2.4 allows obtaining sensitive trace information.
CVE-2012-6344
- EPSS 0.23%
- Veröffentlicht 25.01.2020 19:15:10
- Zuletzt bearbeitet 21.11.2024 01:46:02
Novell ZENworks Configuration Management before 11.2.4 allows XSS.
CVE-2015-0780
- EPSS 3.56%
- Veröffentlicht 09.08.2017 18:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
SQL injection vulnerability in the GetReRequestData method of the GetStoredResult class in Novell ZENworks Configuration Management (ZCM) allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2015-0781
- EPSS 5.57%
- Veröffentlicht 09.08.2017 18:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Directory traversal vulnerability in the doPost method of the Rtrlet class in Novell ZENworks Configuration Management (ZCM) allows remote attackers to upload and execute arbitrary files via unspecified vectors.
CVE-2015-0782
- EPSS 3.54%
- Veröffentlicht 09.08.2017 18:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
SQL injection vulnerability in the ScheduleQuery method of the schedule class in Novell ZENworks Configuration Management (ZCM) allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2015-0783
- EPSS 1.26%
- Veröffentlicht 09.08.2017 18:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The FileViewer class in Novell ZENworks Configuration Management (ZCM) allows remote authenticated users to read arbitrary files via the filename variable.
CVE-2015-0784
- EPSS 3.93%
- Veröffentlicht 09.08.2017 18:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Rtrlet.class in Novell ZENworks Configuration Management (ZCM) allows remote attackers to obtain Session IDs of logged in users via a value of ShowLogins for the maintenance variable.
CVE-2015-0785
- EPSS 2.18%
- Veröffentlicht 09.08.2017 18:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
com.novell.zenworks.inventory.rtr.actionclasses.wcreports in Novell ZENworks Configuration Management (ZCM) allows remote attackers to read arbitrary folders via the dirname variable.
- EPSS 25.33%
- Veröffentlicht 09.08.2017 18:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Stack-based buffer overflow in the logging functionality in the Preboot Policy service in Novell ZENworks Configuration Management (ZCM) allows remote attackers to execute arbitrary code via unspecified vectors.
CVE-2015-5970
- EPSS 0.52%
- Veröffentlicht 18.02.2016 22:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The ChangePassword RPC method in Novell ZENworks Configuration Management (ZCM) 11.3 and 11.4 allows remote attackers to conduct XPath injection attacks, and read arbitrary text files, via a malformed query involving a system entity reference.