XPath Injection Vulnerability in Novell ZENworks Configuration Management
CVE-2015-5970

5.3MEDIUM

Key Information:

Vendor

Novell

Vendor
CVE Published:
18 February 2016

What is CVE-2015-5970?

The ChangePassword RPC method found in Novell ZENworks Configuration Management versions 11.3 and 11.4 is susceptible to XPath injection attacks. Exploiting this vulnerability allows remote attackers to craft a malicious query that manipulates a system entity reference, enabling unauthorized access to read arbitrary text files within the system.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.