Directory Traversal Vulnerability in Novell ZENworks Configuration Management
CVE-2013-1084
Currently unrated
Key Information:
- Vendor
Novell
- Vendor
- CVE Published:
- 2 November 2013
What is CVE-2013-1084?
A directory traversal vulnerability exists in the umaninv service of Novell ZENworks Configuration Management, specifically in the GetFle method. This weakness allows remote attackers to exploit the Filename parameter in a GetFile action, manipulating file paths with '../' sequences to access arbitrary files on the server. Organizations utilizing the affected version should prioritize applying available patches to safeguard against unauthorized file access.