Novell

Zenworks Configuration Management

35 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 5.08%
  • Published 02.11.2013 19:55:04
  • Last modified 11.04.2025 00:51:21

Directory traversal vulnerability in the GetFle method in the umaninv service in Novell ZENworks Configuration Management (ZCM) 11.2.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the Filename parameter in a GetFile action to...

  • EPSS 1.3%
  • Published 17.06.2013 11:38:49
  • Last modified 11.04.2025 00:51:21

Cross-site scripting (XSS) vulnerability in a ZCC page in njwc.jar in Novell ZENworks Configuration Management (ZCM) 11.2 before 11.2.3a Monthly Update 1 allows remote attackers to inject arbitrary web script or HTML via vectors involving an onload e...

  • EPSS 1.3%
  • Published 17.06.2013 11:38:48
  • Last modified 11.04.2025 00:51:21

Cross-site scripting (XSS) vulnerability in a ZCC page in njwc.jar in Novell ZENworks Configuration Management (ZCM) 11.2 before 11.2.3a Monthly Update 1 allows remote attackers to inject arbitrary web script or HTML via vectors involving an onError ...

  • EPSS 2.36%
  • Published 17.06.2013 11:38:48
  • Last modified 11.04.2025 00:51:21

Cross-site scripting (XSS) vulnerability in a ZCC page in zenworks-core in Novell ZENworks Configuration Management (ZCM) 11.2 before 11.2.3a Monthly Update 1 allows remote attackers to inject arbitrary web script or HTML via an invalid locale.

  • EPSS 2.02%
  • Published 17.06.2013 11:38:48
  • Last modified 11.04.2025 00:51:21

Open redirect vulnerability in the fwdToURL function in the ZCC login page in zcc-framework.jar in Novell ZENworks Configuration Management (ZCM) 11.2 before 11.2.3a Monthly Update 1 allows remote attackers to redirect users to arbitrary web sites an...

  • EPSS 72.92%
  • Published 29.03.2013 16:09:05
  • Last modified 11.04.2025 00:51:21

The web server in Novell ZENworks Configuration Management (ZCM) 10.3 and 11.2 before 11.2.4 does not properly perform authentication for zenworks/jsp/index.jsp, which allows remote attackers to conduct directory traversal attacks, and consequently u...

  • EPSS 1.43%
  • Published 29.03.2013 16:09:04
  • Last modified 11.04.2025 00:51:21

Directory traversal vulnerability in the ISCreateObject method in an ActiveX control in InstallShield\ISProxy.dll in AdminStudio in Novell ZENworks Configuration Management (ZCM) 10.3 through 11.2 allows remote attackers to execute arbitrary local DL...

  • EPSS 20.27%
  • Published 26.07.2012 22:55:01
  • Last modified 11.04.2025 00:51:21

Buffer overflow in the DoFindReplace function in the ISGrid.Grid2.1 ActiveX control in InstallShield/ISGrid2.dll in AdminStudio in Novell ZENworks Configuration Management (ZCM) 10.2, 10.3, and 11 SP1 allows remote attackers to execute arbitrary code...

  • EPSS 3.29%
  • Published 26.07.2012 22:55:01
  • Last modified 11.04.2025 00:51:21

The ISList.ISAvi ActiveX control in AdminStudio in Novell ZENworks Configuration Management (ZCM) 10.2, 10.3, and 11 SP1 provides access to the mscomct2.ocx file, which allows remote attackers to execute arbitrary code by leveraging unspecified mscom...

Exploit
  • EPSS 74.4%
  • Published 26.07.2012 22:55:01
  • Last modified 11.04.2025 00:51:21

Directory traversal vulnerability in the LaunchProcess function in the LaunchHelp.HelpLauncher.1 ActiveX control in LaunchHelp.dll in AdminStudio in Novell ZENworks Configuration Management (ZCM) 10.2, 10.3, and 11 SP1 allows remote attackers to exec...