Directory Traversal Vulnerability in Novell Sentinel Log Manager
CVE-2011-5028

Currently unrated

Key Information:

Vendor
Novell
Vendor
CVE Published:
29 December 2011

Summary

The vulnerability in Novell Sentinel Log Manager arises from a directory traversal issue in the FileDownload component. This flaw allows remote authenticated users to access arbitrary files on the server by manipulating the filename parameter with a '..' (dot dot) sequence. As a result, sensitive files may be exposed, posing a significant risk to data security. Proper input validation and restricting file access permissions are crucial to preventing the exploitation of this vulnerability.

References

EPSS Score

14% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.